>
./threat_intel_feed
Curated cybersecurity news from global sources.
BleepingComputer
Sep 17, 2026
Anthropic wants Claude to analyze your bank account and financial data
Anthropic is testing a new personal finance feature called \"Claude Money\" that will allow you to connect your bank accounts directly to Claude and \"understand your money.\" [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-wants-claude-to-analyze-your-bank-account-and-financial-data/)
BleepingComputer
Sep 16, 2026
Windows 11 KB5124008 update breaks domain trust for some users
Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5124008-update-breaks-domain-trust-for-some-users/)
BleepingComputer
Sep 16, 2026
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/)
CyberScoop
Sep 16, 2026
CISA promotes a fresh way to deter cyberattackers: Lie to them
It’s the first guidance from the Cybersecurity and Infrastructure Security Agency on deploying decoys, like honeypots, to detect and distract adversaries.
The post CISA promotes a fresh way to deter cyberattackers: Lie to them appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/cisa-guidance-cyber-decoys-critical-infrastructure/)
BleepingComputer
Sep 16, 2026
Malware bypasses browser checks to force install Chrome, Edge extensions
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/)
BleepingComputer
Sep 16, 2026
Spain's data agency gets first report of AI-powered data breach
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/spains-data-agency-gets-first-report-of-ai-powered-data-breach/)
The Hacker News
Sep 16, 2026
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky.
The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
[Read full article on The Hacker News](https://thehackernews.com/2026/09/three-threat-groups-target-russian.html)
CyberScoop
Sep 16, 2026
Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
The agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the networks of both vessels were compromised.”
The post Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/coast-guard-fbi-investigate-tanker-cyberattacks/)
The Hacker News
Sep 16, 2026
One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension.
Once the extension was installed, it could access each product's built-in AI with a single click. On Comet, Edge,
[Read full article on The Hacker News](https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html)
BleepingComputer
Sep 16, 2026
The true cost of a ransomware attack, with and without BCDR
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr/)
The Hacker News
Sep 16, 2026
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories.
Before the repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted. The worm stole repository secrets and source code for the
[Read full article on The Hacker News](https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html)
BleepingComputer
Sep 16, 2026
Microsoft says Copilot buttons still missing in classic Outlook
Microsoft says it's still investigating a known issue that causes the Copilot and Copilot Chat buttons in Classic Outlook to disappear for some Windows users. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-workaround-for-missing-outlook-copilot-buttons/)
BleepingComputer
Sep 16, 2026
Webinar: What happens in the first hours of a Google Workspace breach
The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/webinar-what-happens-in-the-first-hours-of-a-google-workspace-breach/)
The Hacker News
Sep 16, 2026
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity.
From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud
[Read full article on The Hacker News](https://thehackernews.com/2026/09/n0va-phishkit-targets-us-and-eu.html)
The Hacker News
Sep 16, 2026
Threat Intelligence Alone Won't Close the Exploitation Gap
A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to react.
[Read full article on The Hacker News](https://thehackernews.com/2026/09/threat-intelligence-alone-wont-close.html)
BleepingComputer
Sep 15, 2026
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/)
CyberScoop
Sep 15, 2026
What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies
Three feds spoke about future plans for the Continuous Diagnostics and Mitigation program, and lessons they’ve learned.
The post What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/whats-next-for-cisas-cdm-program-that-gives-cybersecurity-tools-to-federal-agencies/)
The Hacker News
Sep 15, 2026
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN.
Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and
[Read full article on The Hacker News](https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html)
BleepingComputer
Sep 15, 2026
CenterPoint Energy confirms customer data stolen in cyberattack
CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/centerpoint-energy-confirms-customer-data-stolen-in-cyberattack/)
The Hacker News
Sep 15, 2026
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world.
The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record
[Read full article on The Hacker News](https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html)
CyberScoop
Sep 15, 2026
Cisco warns customers of actively exploited zero-day in email gateways
The company confirmed the defect was exploited before it was disclosed and patched, but it did not describe the nature of the attacks or the scope of impact across its customer base.
The post Cisco warns customers of actively exploited zero-day in email gateways appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited/)
The Hacker News
Sep 15, 2026
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems.
The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.
[Read full article on The Hacker News](https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html)
BleepingComputer
Sep 15, 2026
BambooToken malware controls Windows and Linux systems via MQTT
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt/)
BleepingComputer
Sep 15, 2026
Hackers target WordPress sites via third-party WooCommerce plugin
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/)
BleepingComputer
Sep 15, 2026
What Zero-Day Response Should Be in the Post-Mythos Era
AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/what-zero-day-response-should-be-in-the-post-mythos-era/)
The Hacker News
Sep 15, 2026
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access.
In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH
[Read full article on The Hacker News](https://thehackernews.com/2026/09/human-attacker-exploits-marimo-rce.html)
The Hacker News
Sep 15, 2026
Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point
Introduction
Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature organizations, this testing happens continuously rather than as a one-off exercise.
But no matter how much you validate against these
[Read full article on The Hacker News](https://thehackernews.com/2026/09/attack-chains-not-just-attack-surfaces.html)
BleepingComputer
Sep 15, 2026
Suspected Black Axe gang leaders face cybercrime charges in the US
Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/black-axe-gang-members-extradited-to-us-face-cybercrime-charges/)
BleepingComputer
Sep 15, 2026
Microsoft confirms KB5002914 Excel update breaks copy and paste
Microsoft has confirmed that copy and paste may silently fail for some Excel users after installing the September 2026 KB5002914 security update. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-september-kb5002914-security-update-breaks-excel-copy-and-paste/)
CyberScoop
Sep 15, 2026
Supreme Court denies Trump request to allow USPS mail ballot changes
One justice said the attempt to change the rules ahead of the 2026 elections would be \"arbitrary and capricious” and violated the Administrative Procedures Act.
The post Supreme Court denies Trump request to allow USPS mail ballot changes appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/supreme-court-denies-trump-usps-mail-ballot-changes/)
BleepingComputer
Sep 14, 2026
Microsoft releases emergency Windows updates to fix RDS failures
Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-emergency-windows-updates-to-fix-rds-failures/)
BleepingComputer
Sep 14, 2026
Homebrew 7.0.0 gets built-in GUI, better security controls
Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/homebrew-700-gets-built-in-gui-better-security-controls/)
BleepingComputer
Sep 14, 2026
Twitch extension with 30K installs exposes users’ OAuth tokens
A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users' Twitch OAuth session tokens to a commercial bot service. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/twitch-extension-with-30k-installs-exposes-users-oauth-tokens/)
CyberScoop
Sep 14, 2026
Five alleged leaders of Black Axe’s operations in South Africa extradited to US
Officials said the five individuals concocted various long-running romance scams to trick U.S.-based victims into sending them money.
The post Five alleged leaders of Black Axe’s operations in South Africa extradited to US appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/black-axe-south-africa-leaders-extradited/)
BleepingComputer
Sep 14, 2026
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/)
The Hacker News
Sep 14, 2026
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said.
The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of
[Read full article on The Hacker News](https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html)
The Hacker News
Sep 14, 2026
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it were current.
The attack requires an attacker who already controls the server's software and can briefly access the machine to insert a small circuit
[Read full article on The Hacker News](https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html)
The Hacker News
Sep 14, 2026
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
A Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign.
\"Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems,\" Acronis Threat Research Unit (TRU) said in an
[Read full article on The Hacker News](https://thehackernews.com/2026/09/red-heron-exploits-gitea-rce-to.html)
BleepingComputer
Sep 14, 2026
Hackers target exposed Vite dev servers to steal AWS, Azure secrets
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/)
The Hacker News
Sep 14, 2026
WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved.
\"New plugins are reviewed before they enter the directory, but updates ship continuously after that,\" David Perez, WordPress Official Plugin
[Read full article on The Hacker News](https://thehackernews.com/2026/09/wordpress-adds-automated-plugin-reviews.html)
The Hacker News
Sep 14, 2026
⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination.
The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of
[Read full article on The Hacker News](https://thehackernews.com/2026/09/weekly-recap-rogue-ai-agents-wechat.html)
BleepingComputer
Sep 14, 2026
Webinar: How malicious OAuth apps can lead to Google Workspace breaches
Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. This webinar examines two attacks to show how these breaches unfold and which security controls can help stop them. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/webinar-how-malicious-oauth-apps-can-lead-to-google-workspace-breaches/)
The Hacker News
Sep 14, 2026
AI Changed the Exposure Problem. Validation Needs to Change With It.
There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action.
In the first half of 2026, a whopping 35,853 CVEs were published, roughly 49% more than in the
[Read full article on The Hacker News](https://thehackernews.com/2026/09/ai-changed-exposure-problem-validation.html)
BleepingComputer
Sep 14, 2026
Microsoft: September updates cause RDS failures on Windows Server
Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-september-updates-cause-rds-failures-on-windows-server/)
BleepingComputer
Sep 14, 2026
Revolut discloses data breach exposing financial info, passports
Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/revolut-discloses-data-breach-exposing-financial-info-passports/)
BleepingComputer
Sep 14, 2026
Microsoft: September updates break audio on some Windows PCs
Microsoft has confirmed that USB audio devices may fail on some Windows systems after installing the KB5124008and KB5124012 September 2026 security updates. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-september-updates-break-audio-on-some-windows-pcs/)
The Hacker News
Sep 14, 2026
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service.
The extension, named \"Twitch Enhanced Viewer | JeetBot,\" lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store -
Chrome -
[Read full article on The Hacker News](https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html)
The Hacker News
Sep 13, 2026
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments.
The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers
[Read full article on The Hacker News](https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html)
The Hacker News
Sep 12, 2026
When the Whole Company Adopts AI: What It Does to Your SOC
Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and non-technical staff signing consumer AI tools into corporate
[Read full article on The Hacker News](https://thehackernews.com/2026/09/when-whole-company-adopts-ai-what-it.html)
The Hacker News
Sep 12, 2026
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The \"major malicious attack\" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx.
On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the
[Read full article on The Hacker News](https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html)
CyberScoop
Sep 12, 2026
Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems
OpenAI confirmed their agents were behind a campaign in May that researchers say flooded the popular online code repository with malicious software packages.
The post Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/openai-agents-malicious-rubygems-packages/)
BleepingComputer
Sep 11, 2026
Hackers abused Claude to extract secrets from 1.8M Android apps
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/)
BleepingComputer
Sep 11, 2026
Florida confirms DMV database breached via stolen police account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/)
BleepingComputer
Sep 11, 2026
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/)
The Hacker News
Sep 11, 2026
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax.
Knowledge distillation by itself is a legitimate training method. It refers to a machine learning technique where a large, powerful AI model assumes the role of a \"teacher\" to
[Read full article on The Hacker News](https://thehackernews.com/2026/09/anthropic-says-seven-china-based-ai.html)
The Hacker News
Sep 11, 2026
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026.
The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial
[Read full article on The Hacker News](https://thehackernews.com/2026/09/claude-used-to-automate-exploitation.html)
The Hacker News
Sep 11, 2026
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve.
The operation has been attributed to a cyber espionage group it calls GTG-20006 (where \"GTG\" stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight
[Read full article on The Hacker News](https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html)
BleepingComputer
Sep 11, 2026
How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/)
The Hacker News
Sep 11, 2026
Your Critical Vulnerabilities Might Not Be Your Biggest Risk
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise.
A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent an attacker
[Read full article on The Hacker News](https://thehackernews.com/2026/09/your-critical-vulnerabilities-might-not.html)
BleepingComputer
Sep 11, 2026
Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs
Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-teams-outlook-launch-failures-on-arm-windows-pcs/)
BleepingComputer
Sep 11, 2026
Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/)
BleepingComputer
Sep 11, 2026
Conti ransomware gang member sentenced to 4 years in prison
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/conti-ransomware-gang-member-sentenced-to-four-years-in-prison/)
BleepingComputer
Sep 10, 2026
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/)
BleepingComputer
Sep 10, 2026
September Windows Server updates break Remote Desktop Services
Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/september-windows-server-updates-break-remote-desktop-services/)
CyberScoop
Sep 10, 2026
Conti ransomware crew member sentenced to four years in prison
Oleksii Lytvynenko joined the notorious group in 2021 and was directly involved in attacks on at least 12 companies.
The post Conti ransomware crew member sentenced to four years in prison appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/conti-ransomware-developer-sentenced/)
CyberScoop
Sep 10, 2026
AI lets small actors run state-level hacking campaigns, Anthropic report finds
The report details a Russian-aligned espionage campaign against more than 20 organizations, an exploit foundry run by Chinese undergraduates and ShinyHunters-affiliated breaches, among other disrupted operations.
The post AI lets small actors run state-level hacking campaigns, Anthropic report finds appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/anthropic-report-ai-enabled-cyber-attacks/)
BleepingComputer
Sep 10, 2026
Surfshark VPN says hackers breached internal testing, proxy servers
Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/surfshark-vpn-says-hackers-breached-internal-testing-proxy-servers/)
BleepingComputer
Sep 10, 2026
Microsoft Excel KB5002914 update breaks copy and paste for some users
Microsoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-excel-kb5002914-update-breaks-copy-and-paste-for-some-users/)
BleepingComputer
Sep 10, 2026
IDScan confirms breach tied to 153 million stolen driver’s licenses
Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/)
The Hacker News
Sep 10, 2026
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content.
Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their
[Read full article on The Hacker News](https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html)
BleepingComputer
Sep 10, 2026
The Top 4 Threats We Found by Investigating Every Alert for a Quarter
Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/the-top-4-threats-we-found-by-investigating-every-alert-for-a-quarter/)
CyberScoop
Sep 10, 2026
Governments ‘buying time’ in race between innovation, security, national cyber director says
Sean Cairncross also said AI has shown long-standing issues in cyber rather than creating new ones.
The post Governments ‘buying time’ in race between innovation, security, national cyber director says appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/national-cyber-director-ai-cybersecurity-threats/)
The Hacker News
Sep 10, 2026
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9.
A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That
[Read full article on The Hacker News](https://thehackernews.com/2026/09/gigabud-creates-android-work-profiles.html)
BleepingComputer
Sep 10, 2026
Microsoft says September updates fix mouse settings reset issues
Microsoft has fixed a known issue that wiped mouse settings on some Windows 11 systems after installing the KB5120998 August 2026 preview update. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-resolves-mouse-settings-reset-bug-windows-11-update/)
BleepingComputer
Sep 10, 2026
Microsoft fixes bug that wiped Windows desktop settings
Microsoft says the September 2026 Patch Tuesday updates fix a known issue causing desktop settings to be lost or reset on some Windows devices. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bug-that-wiped-windows-desktop-settings/)
The Hacker News
Sep 10, 2026
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide.
LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential.
Anyone who holds it can read every
[Read full article on The Hacker News](https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html)
The Hacker News
Sep 10, 2026
Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents.
The AI company said the incident dates back to January 2026 and involved an early version of Claude Opus 4.6 that breached \"
[Read full article on The Hacker News](https://thehackernews.com/2026/09/anthropic-ai-models-breached-real.html)
BleepingComputer
Sep 10, 2026
Trezor warns users of email provider breach, phishing attacks
Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/)
BleepingComputer
Sep 9, 2026
AdaptHealth confirms 4.1 million people exposed in July cyberattack
Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-people-exposed-in-july-cyberattack/)
CyberScoop
Sep 9, 2026
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Multiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen.
The post Chinese espionage groups swarm to exploit triple-link chain of zero-days appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/china-espionage-groups-exploit-chain-zero-days/)
BleepingComputer
Sep 9, 2026
Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking
The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/skullcandy-dime-3-earbuds-expose-users-to-bluetooth-hijacking/)
CyberScoop
Sep 9, 2026
FTC rescinds policy requiring health apps to notify customers after a breach
The policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization.
The post FTC rescinds policy requiring health apps to notify customers after a breach appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/ftc-rescinds-health-app-data-breach-policy/)
The Hacker News
Sep 9, 2026
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime
[Read full article on The Hacker News](https://thehackernews.com/2026/09/us-disrupts-xinbi-guarantee-scam.html)
BleepingComputer
Sep 9, 2026
US says Chinese firms extracted billions of tokens from frontier AI models
U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/us-says-chinese-firms-extracted-billions-of-tokens-from-frontier-ai-models/)
The Hacker News
Sep 9, 2026
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.
The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,
[Read full article on The Hacker News](https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html)
BleepingComputer
Sep 9, 2026
Veradigm warns of patient data breach after ransomware gang claims attack
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/veradigm-discloses-patient-data-breach-after-gentlemen-gang-claims-attack/)
CyberScoop
Sep 9, 2026
FBI cyber chief worries private sector not sharing enough cyber threat information
Brett Leatherman said that industry has the wrong idea about what the FBI does with the data it collects during incidents, which is used to help victims and investigations alike.
The post FBI cyber chief worries private sector not sharing enough cyber threat information appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/fbi-cyber-division-private-sector-threat-sharing/)
The Hacker News
Sep 9, 2026
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create \"stolen keys\" that grant illicit access to tools from model providers like Google, Anthropic, and others.
Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API
[Read full article on The Hacker News](https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html)
BleepingComputer
Sep 9, 2026
MFA's Weakest Link: Account Recovery Is the New Attack Path
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/mfas-weakest-link-account-recovery-is-the-new-attack-path/)
CyberScoop
Sep 9, 2026
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
The remarks, to both CyberScoop and at the Billington CyberSecurity Summit, dovetail with the release of a new bureau cyber strategy.
The post FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/fbi-cyber-strategy-ai-threats-patching/)
The Hacker News
Sep 9, 2026
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed?
For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act.
As AI accelerates vulnerability discovery and research, that delay matters more
[Read full article on The Hacker News](https://thehackernews.com/2026/09/webinar-learn-how-to-answer-are-we.html)
The Hacker News
Sep 9, 2026
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting \"systematic extraction\" of proprietary functionalities and capabilities of American frontier models through distillation attacks.
The activity has been described as occurring at an industrial-scale and one that forms the \"core\" of their AI development strategy, according to
[Read full article on The Hacker News](https://thehackernews.com/2026/09/us-agencies-accuse-china-ai-firms-of.html)
The Hacker News
Sep 9, 2026
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.
The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine.
\"Out-of-bounds write in V8 in Google Chrome prior to
[Read full article on The Hacker News](https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html)
BleepingComputer
Sep 9, 2026
Man gets 15 years for extorting women with AI-generated porn videos
An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/man-gets-15-years-in-prison-for-cyberstalking-and-sextortion/)
CyberScoop
Sep 8, 2026
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
While the vendor hit another monthly record, it hasn’t resulted in a flood of active exploits. Researchers encourage customers to focus on their specific areas of risk and exposure.
The post Microsoft discloses two actively exploited zero-days among 974 vulnerabilities appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/microsoft-patch-tuesday-september-2026/)
CyberScoop
Sep 8, 2026
Feds accuse China of ‘systematic’ distillation of U.S. AI models
A joint advisory alleges Chinese companies are using sophisticated systems to route millions of data requests to US AI models across different accounts and platforms.
The post Feds accuse China of ‘systematic’ distillation of U.S. AI models appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/us-accuses-chinese-ai-companies-distillation/)
BleepingComputer
Sep 8, 2026
DoppelCart fraud network uses 119,000 fake shops to steal credit cards
A massive operation dubbed \"DoppelCart\" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/doppelcart-fraud-network-uses-119-000-fake-shops-to-steal-credit-cards/)
CyberScoop
Sep 8, 2026
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Authorities accuse the 36-year-old and co-conspirators of collecting more than 5,000 victim login credentials to various banks.
The post Russian national extradited to US for alleged involvement in bank-account takeover scheme appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/russian-national-extradited-bank-account-takeover-sergei-filimonov/)
BleepingComputer
Sep 8, 2026
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-breach-f5-big-ip-apm-devices-to-deploy-linux-rootkit/)
CyberScoop
Sep 8, 2026
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The deputy director cited Operation Absolute Resolve as evidence that cyber teams have become central to CIA missions.
The post CIA’s Michael Ellis says cyber intelligence is changing how the agency operates appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/cia-cyber-operations-operation-absolute-resolve-michael-ellis-billington-cybersecurity/)
BleepingComputer
Sep 8, 2026
Microsoft releases Windows 10 KB5122878 extended security update
Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5122878-extended-security-update/)
CyberScoop
Sep 8, 2026
Why federal cyber defense demands an offense-driven mindset
Static checklists and annual penetration tests leave agencies with dangerous blind spots. True resilience requires moving from reactive attestation to continuous, automated validation.
The post Why federal cyber defense demands an offense-driven mindset appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/offense-driven-federal-cyber-defense/)
BleepingComputer
Sep 8, 2026
Windows 11 cumulative updates KB5124008 & KB5122880 released
Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/windows-11-cumulative-updates-kb5124008-and-kb5122880-released/)
BleepingComputer
Sep 8, 2026
ShinyHunters hackers claim breach of Florida "DAVID" DMV database
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as \"DAVID\" and stole over 200,000 records about drivers in the state. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/)
BleepingComputer
Sep 8, 2026
OpenAI says ChatGPT outage causes image generation errors
OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/technology/openai-says-chatgpt-outage-causes-image-generation-errors/)
The Hacker News
Sep 8, 2026
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026.
Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider.
\"The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment
[Read full article on The Hacker News](https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html)
BleepingComputer
Sep 8, 2026
August updates trigger 0xc0000409 errors on Windows Server 2016
Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/august-updates-trigger-0xc0000409-errors-on-windows-server-2016/)
The Hacker News
Sep 8, 2026
Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC
Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back.
Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC. The network is still paused, so holders cannot turn that token back into bitcoin.
The 3,400 bitcoin was sent to a&
[Read full article on The Hacker News](https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html)
BleepingComputer
Sep 8, 2026
OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor
OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the \"Critical level\" for cybersecurity capabilities. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/artificial-intelligence/openai-says-gpt-6-astra-can-find-zero-days-but-is-also-harder-to-monitor/)
The Hacker News
Sep 8, 2026
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours.
Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI
[Read full article on The Hacker News](https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html)
BleepingComputer
Sep 8, 2026
Adobe fixes critical Magento zero-day exploited to backdoor servers
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-magento-zero-day-exploited-to-backdoor-servers/)
BleepingComputer
Sep 8, 2026
Webinar: The forgotten Google Workspace access that can lead to a breach
Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposure. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/webinar-the-forgotten-google-workspace-access-that-can-lead-to-a-breach/)
The Hacker News
Sep 8, 2026
What It Took to Reach 1 Billion Build Manifests
In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally
[Read full article on The Hacker News](https://thehackernews.com/2026/09/what-it-took-to-reach-1-billion-build.html)
CyberScoop
Sep 8, 2026
In most cities, nobody owns the whole network
July’s intrusions reached water controllers that sat on a cellular link no city network scan would find. Naming an owner and paying for the fix are decisions a utility can make this fiscal year, out of money it already applies for.
The post In most cities, nobody owns the whole network appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/water-utility-cybersecurity-network-segmentation-op-ed/)
The Hacker News
Sep 8, 2026
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams.
The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect
[Read full article on The Hacker News](https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html)
BleepingComputer
Sep 8, 2026
220 million traveler records exposed in Vietnam-linked APIS leak
Exclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Researchers accessed the Vietnam-linked system through a cloud-based path using default credentials. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/)
The Hacker News
Sep 7, 2026
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser.
\"Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences
[Read full article on The Hacker News](https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html)
BleepingComputer
Sep 7, 2026
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
A zero-day vulnerability dubbed \"StyleSmuggler\" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/magento-stylesmuggler-zero-day-exploited-to-deploy-linux-backdoor/)
The Hacker News
Sep 7, 2026
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins.
The activity, which mainly singles out directors, vice presidents, and other executive staff
[Read full article on The Hacker News](https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html)
BleepingComputer
Sep 7, 2026
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/)
The Hacker News
Sep 7, 2026
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.
Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management
[Read full article on The Hacker News](https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html)
BleepingComputer
Sep 7, 2026
Mathspace discloses data breach affecting over 1 million people
Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/)
BleepingComputer
Sep 7, 2026
Trezor data breach impact now reaches 81,000 customers
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/)
The Hacker News
Sep 7, 2026
Your Cloud Security Checklist Doesn't Work the Way You Think It Does
If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like.
How risk differs across cloud providers
[Read full article on The Hacker News](https://thehackernews.com/2026/09/your-cloud-security-checklist-doesnt.html)
The Hacker News
Sep 7, 2026
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems.
According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake
[Read full article on The Hacker News](https://thehackernews.com/2026/09/rogue-screenconnect-clients-spread-four.html)
The Hacker News
Sep 7, 2026
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
A TantoSec proof-of-concept turns an AES-CBC \"padding oracle\" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild.
Security firm TantoSec has published a working exploit chain targeting vulnerabilities
[Read full article on The Hacker News](https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html)
BleepingComputer
Sep 7, 2026
ChatGPT can now connect to your personal apps to mimic writing style
OpenAI appears to be testing a new \"Writing Style\" feature for ChatGPT that can learn how you write by looking at examples from your connected apps. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/artificial-intelligence/chatgpt-can-now-connect-to-your-personal-apps-to-mimic-writing-style/)
The Hacker News
Sep 7, 2026
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities.
\"The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers,\" Check Point Research said in a
[Read full article on The Hacker News](https://thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html)
BleepingComputer
Sep 7, 2026
ChatGPT Astra is now rolling out to $20 Plus subscription
OpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there's no word on when free users will get access.. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/artificial-intelligence/chatgpt-astra-is-now-rolling-out-to-20-plus-subscription/)
BleepingComputer
Sep 6, 2026
Attackers conceal phishing lures using invisible Unicode characters
Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/)
The Hacker News
Sep 6, 2026
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5.
Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or
[Read full article on The Hacker News](https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html)
The Hacker News
Sep 6, 2026
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself.
One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.
The company named the four programs ProManager, WinUpdate, SoftManager, and
[Read full article on The Hacker News](https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html)
The Hacker News
Sep 5, 2026
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment.
\"Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions,\" JetBrains said.
[Read full article on The Hacker News](https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html)
BleepingComputer
Sep 5, 2026
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/over-5-400-hacked-sites-serve-clickfix-payloads-stored-on-the-blockchain/)
The Hacker News
Sep 5, 2026
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk.
The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets
[Read full article on The Hacker News](https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html)
BleepingComputer
Sep 5, 2026
OpenAI admits it didn't disclose rogue AI wiki hijacking incident
OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model \"misalignment\" rather than a security breach. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/)
The Hacker News
Sep 5, 2026
Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox.
The activity was concentrated on DSEwiki, a German software developer wiki that runs
[Read full article on The Hacker News](https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html)
CyberScoop
Sep 4, 2026
European parliament members call for slowdown of Serbia’s EU entry over spyware use
The letter follows revelations about Serbian student activists being infected with Pegasus and NoviSpy, and coincides with other pressures on Belgrade.
The post European parliament members call for slowdown of Serbia’s EU entry over spyware use appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/eu-parliament-serbia-accession-spyware-demands/)
The Hacker News
Sep 4, 2026
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a \"high-volume phishing campaign\" that's using invisible Unicode tag characters to bypass email filters.
\"Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them,\" the Microsoft Security Research team said.
The
[Read full article on The Hacker News](https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html)
The Hacker News
Sep 4, 2026
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors.
The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and
[Read full article on The Hacker News](https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html)
BleepingComputer
Sep 4, 2026
Microsoft says some users can’t open the Teams desktop client
Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-says-some-users-cant-open-the-teams-desktop-client/)
BleepingComputer
Sep 4, 2026
39 New Methods That Compromise Passkey Authentication
Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/39-new-methods-that-compromise-passkey-authentication/)
BleepingComputer
Sep 4, 2026
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
An anonymous security researcher who uses the \"Nightmare Eclipse\" handle released a CrowdStrike Falcon zero-day exploit named \"FalconFlank\" that lets attackers escalate privileges on up-to-date Windows systems. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/)
BleepingComputer
Sep 4, 2026
Exchange Online outage causes email delays, 'Server busy' errors
Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/exchange-online-outage-causes-email-delays-server-busy-errors/)
CyberScoop
Sep 4, 2026
Why judgment is emerging as cybersecurity’s defining skill
AI is getting better at much of what security teams have long spent time on: analyzing information, identifying patterns, and providing technically sound recommendations quickly. As those capabilities become more routine, they are changing what security practitioners spend their time on. Reaching a technically sound recommendation is also getting easier, which puts more weight on […]
The post Why judgment is emerging as cybersecurity’s defining skill appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/ai-security-operations-human-context-ciso-op-ed/)
The Hacker News
Sep 4, 2026
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild.
The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine.
\"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote
[Read full article on The Hacker News](https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html)
The Hacker News
Sep 4, 2026
GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests
OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the \"world's most intelligent and aligned model.\"
The development comes days after the artificial intelligence (AI) company said the model had reached the \"Critical\" cybersecurity capability threshold under its Preparedness Framework.
\"Astra is state-of-the-art on computer use, browsing, software engineering,
[Read full article on The Hacker News](https://thehackernews.com/2026/09/gpt-6-astra-scores-100-on-exploitbench.html)
CyberScoop
Sep 3, 2026
Attackers exploit zero-days in consistently besieged SonicWall product
SonicWall customers have confronted a barrage of attacks for years, including five actively exploited vulnerabilities in SMA 1000 appliances since late 2025.
The post Attackers exploit zero-days in consistently besieged SonicWall product appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/sonicwall-sma1000-zero-days-actively-exploited/)
BleepingComputer
Sep 3, 2026
Coder's registry infrastructure compromised to push malicious modules
Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/coders-registry-infrastructure-compromised-to-push-malicious-modules/)
CyberScoop
Sep 3, 2026
The G7 tells industry to hurry up and prep for post-quantum encryption
The nations warn that governments and industry can no longer treat quantum codebreaking as a distant or theoretical possibility.
The post The G7 tells industry to hurry up and prep for post-quantum encryption appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/g7-quantum-computing-encryption-warning/)
The Hacker News
Sep 3, 2026
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door?
That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough.
There is also
[Read full article on The Hacker News](https://thehackernews.com/2026/09/threatsday-ceo-phishing-kits-5k-dropbox.html)
The Hacker News
Sep 3, 2026
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.
\"Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial
[Read full article on The Hacker News](https://thehackernews.com/2026/09/brazetsu-malware-turns-compromised.html)
BleepingComputer
Sep 3, 2026
Microsoft: KB5120998 mouse reset bug affects only non-English PCs
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-kb5120998-mouse-reset-bug-affects-only-non-english-pcs/)
BleepingComputer
Sep 3, 2026
OpenAI confirms ChatGPT is down ahead of 'Astra' model launch
ChatGPT and Codex are experiencing a major outage, with users reporting errors across nearly every major ChatGPT feature. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/artificial-intelligence/openai-confirms-chatgpt-is-down-ahead-of-astra-model-launch/)
BleepingComputer
Sep 3, 2026
Anthropic confirms Claude is down, multiple models affected
Claude is experiencing an outage, with users encountering elevated errors when sending requests to multiple Anthropic AI models. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-confirms-claude-is-down-multiple-models-affected/)
The Hacker News
Sep 3, 2026
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada.
West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names
[Read full article on The Hacker News](https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html)
BleepingComputer
Sep 3, 2026
Your Employee’s Password Appeared in an Infostealer Log. Now What?
Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/your-employees-password-appeared-in-an-infostealer-log-now-what/)
BleepingComputer
Sep 3, 2026
Microsoft says KB5120998 Windows update resets desktop settings
Microsoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-says-kb5120998-windows-update-resets-desktop-settings/)
The Hacker News
Sep 3, 2026
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries.
Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses
[Read full article on The Hacker News](https://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.html)
BleepingComputer
Sep 3, 2026
Plex warns users to patch security vulnerabilities immediately
Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/)
The Hacker News
Sep 3, 2026
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.
According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026.
\"The technique's appeal is that node.exe (the
[Read full article on The Hacker News](https://thehackernews.com/2026/09/attackers-turn-trusted-nodejs-runtime.html)
The Hacker News
Sep 3, 2026
Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means
In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs.
Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have
[Read full article on The Hacker News](https://thehackernews.com/2026/09/shai-huluds-reach-just-grew-to-469.html)
BleepingComputer
Sep 3, 2026
Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs
Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-outlook-fail-to-launch-on-arm-based-windows-pcs/)
The Hacker News
Sep 3, 2026
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation.
\"Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware,\" the Citizen Lab said. \"We found high-confidence indicators of
[Read full article on The Hacker News](https://thehackernews.com/2026/09/pegasus-zero-click-spyware-exploit.html)
The Hacker News
Sep 2, 2026
Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program.
\"The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them
[Read full article on The Hacker News](https://thehackernews.com/2026/09/google-anthropic-and-openai-unveil.html)
CyberScoop
Sep 2, 2026
Dogged Russia-based botnet dismantled after 23-year run
Sality’s peer-to-peer infrastructure allowed it to evade system-wide disruption efforts for an exceptionally long period. Authorities and cybersecurity experts finally brought it down.
The post Dogged Russia-based botnet dismantled after 23-year run appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/sality-botnet-dismantled/)
The Hacker News
Sep 2, 2026
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.
\"The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users,\" Microsoft
[Read full article on The Hacker News](https://thehackernews.com/2026/09/fake-software-installers-disable.html)
CyberScoop
Sep 2, 2026
Pegasus, NoviSpy variant spyware found on devices of Serbian activists
It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia yet.
The post Pegasus, NoviSpy variant spyware found on devices of Serbian activists appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/pegasus-novispy-variant-spyware-found-on-devices-of-serbian-activists/)
CyberScoop
Sep 2, 2026
Wyden seeks upgraded NSA security guidance on commercial VPN use
it’s the latest in a sequence of letters to feds from Sen. Ron Wyden, D-Ore., on commercial VPNs.
The post Wyden seeks upgraded NSA security guidance on commercial VPN use appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/wyden-nsa-commercial-vpn-security-guidance/)
BleepingComputer
Sep 2, 2026
Ransomware protection for MSPs: A 6-point checklist for faster recovery
Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/ransomware-protection-for-msps-a-6-point-checklist-for-faster-recovery/)
The Hacker News
Sep 2, 2026
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting.
Check Point Research said it has tracked the campaign since mid-2025.
The modules
[Read full article on The Hacker News](https://thehackernews.com/2026/09/malicious-apache-modules-hijack.html)
The Hacker News
Sep 2, 2026
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise.
The incident window ran from approximately August 28 at 20:57
[Read full article on The Hacker News](https://thehackernews.com/2026/09/bgp-hijack-delivers-malicious.html)
The Hacker News
Sep 2, 2026
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices.
ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union
[Read full article on The Hacker News](https://thehackernews.com/2026/09/meta-ads-push-streamrat-android-trojan.html)
The Hacker News
Sep 2, 2026
How to Secure Enterprise AI: From Adoption to Incident Readiness
The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to move fast. Organizations must focus on adopting AI at business speed without losing control of cyber risk. Download the full eBook here.
The Business Reality
In Sygnia’s 2026 CISO Survey Report, which
[Read full article on The Hacker News](https://thehackernews.com/2026/09/how-to-secure-enterprise-ai-from.html)
BleepingComputer
Sep 2, 2026
Microsoft Defender flags legitimate Google search links as malicious
Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/microsoft-defender-flags-legitimate-google-search-links-as-malicious/)
The Hacker News
Sep 2, 2026
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals.
The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31.
GeoNetwork originated at the United Nations Food and
[Read full article on The Hacker News](https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html)
The Hacker News
Sep 2, 2026
Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.
Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025, the U.S. Attorney's Office for the Northern District of California
[Read full article on The Hacker News](https://thehackernews.com/2026/09/extradited-russian-hacker-faces-charges.html)
BleepingComputer
Sep 2, 2026
US charges Russian for infecting 80,000 freelancers with malware
A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/us-charges-russian-for-infecting-80-000-freelancers-with-malware/)
The Hacker News
Sep 2, 2026
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware.
The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command
[Read full article on The Hacker News](https://thehackernews.com/2026/09/researchers-use-claude-to-port-pre-auth.html)
CyberScoop
Sep 1, 2026
FBI raises alarm over deceptive phishing campaign targeting prominent people
The ongoing social engineering threat, which dates back to late 2025, tricks victims into granting threat actors long-term access to their accounts.
The post FBI raises alarm over deceptive phishing campaign targeting prominent people appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/fbi-alert-oauth-consent-phishing-campaign/)
BleepingComputer
Sep 1, 2026
Hackers abuse Faronics Deploy admin tool to install ScreenConnect
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/)
CyberScoop
Sep 1, 2026
Tina Peters, through attorney, backs off formal role in Shasta County elections
Peters still left the door open to working with Shasta County on elections and doubled down on her statements that electronic voting machines should be discontinued.
The post Tina Peters, through attorney, backs off formal role in Shasta County elections appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/tina-peters-shasta-county-election-role/)
BleepingComputer
Sep 1, 2026
Aesto Health says data breach affects over 9.5 million patients
Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/aesto-health-says-data-breach-affects-over-95-million-patients/)
The Hacker News
Sep 1, 2026
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024.
Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as \"specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers.\" The adversary
[Read full article on The Hacker News](https://thehackernews.com/2026/09/breeze-comet-executes-hundreds-of.html)
BleepingComputer
Sep 1, 2026
Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack/)
BleepingComputer
Sep 1, 2026
Novocure data breach affects more than 1,400 cancer patients
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/novocure-data-breach-affects-more-than-1-400-cancer-patients/)
The Hacker News
Sep 1, 2026
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices.
\"The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect
[Read full article on The Hacker News](https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html)
BleepingComputer
Sep 1, 2026
Why Even the Best Edge Security Still Misses High-Risk Sessions
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/why-even-the-best-edge-security-still-misses-high-risk-sessions/)
CyberScoop
Sep 1, 2026
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
The Federal Ballot Mail Portal is described by a federal official as one of several IT systems that will be used to potentially deny thousands of mail-in ballots or more to states.
The post Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/usps-whistleblower-ballot-system-2026-midterms/)
The Hacker News
Sep 1, 2026
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript.
Russian cybersecurity company Kaspersky is tracking the
[Read full article on The Hacker News](https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html)
BleepingComputer
Sep 1, 2026
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/)
The Hacker News
Sep 1, 2026
Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
The most common way into a company last year was to ask.
A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year, accounting
[Read full article on The Hacker News](https://thehackernews.com/2026/09/threat-actors-dont-want-better-attacks.html)
CyberScoop
Sep 1, 2026
The Collective Cyber Defense letter wrote your next vendor questionnaire
More than 200 companies have now signed to an August 27 letter about improving cyber defenses in the age of AI. Buried in it are three metrics every one of them endorse under its own logo: coverage, containment speed, and whether fixes work.
The post The Collective Cyber Defense letter wrote your next vendor questionnaire appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/collective-cyber-defense-letter-vendor-questionnaire-op-ed/)
BleepingComputer
Sep 1, 2026
Five Venezuelans plead guilty to ATM jackpotting attacks in US
Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/five-venezuelans-plead-guilty-to-atm-jackpotting-attacks-in-us/)
The Hacker News
Sep 1, 2026
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
METR (short for Model Evaluation and Threat Research and pronounced \"Meter\"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered \"two notable security incidents\" where external actors attempted to gain unauthorized access to its systems.
No sensitive information is believed to
[Read full article on The Hacker News](https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html)
The Hacker News
Sep 1, 2026
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis.
The idea, ESET said in a series of posts on X, is to deliberately trip a large language model's (LLM) safety mechanisms and prevent its
[Read full article on The Hacker News](https://thehackernews.com/2026/09/russia-aligned-uac-0099-plants-nuclear.html)
BleepingComputer
Sep 1, 2026
Recently patched PaperCut zero-days used in data theft attacks
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/recently-patched-papercut-zero-days-used-in-data-theft-attacks/)
CyberScoop
Aug 31, 2026
McKesson copes with fallout from data theft extortion attack
The major healthcare sector vendor did not identify the attackers, but ShinyHunters, a prolific group increasingly targeting the sector, claimed responsibility.
The post McKesson copes with fallout from data theft extortion attack appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/mckesson-data-theft-extortion-attack-shinyhunters/)
BleepingComputer
Aug 31, 2026
Cronos blockchain restarts after $74 million Tectonic exploit
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/cronos-blockchain-restarts-after-74-million-tectonic-exploit/)
BleepingComputer
Aug 31, 2026
Microsoft warns of TerminalFix attacks deploying reverse tunnels
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/microsoft-warns-of-terminalfix-attacks-deploying-reverse-tunnels/)
CyberScoop
Aug 31, 2026
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
The six-month program will be overseen by the Office of the National Cyber Director and Texas Cyber Command to “find out what works.”
The post ‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/watershed-250-texas-water-cybersecurity-pilot/)
The Hacker News
Aug 31, 2026
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession.
The ongoing insider threat is part of what has been described as the IT worker scheme,
[Read full article on The Hacker News](https://thehackernews.com/2026/08/north-korean-job-fraud-expands-beyond.html)
BleepingComputer
Aug 31, 2026
Microsoft Exchange Online outage causes email failures, auth issues
Microsoft is investigating a widespread service issue causing authentication issues, email delays and failures, and various other issues for Exchange Online customers. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-online-outage-causes-email-failures-auth-issues/)
BleepingComputer
Aug 31, 2026
OpenAI confirms ChatGPT outage as users report errors
ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/artificial-intelligence/openai-confirms-chatgpt-outage-as-users-report-errors/)
BleepingComputer
Aug 31, 2026
Chinese Fire Ant hackers turn Cisco routers into spying platforms
The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/)
BleepingComputer
Aug 31, 2026
File servers are here to stay. Here’s how to manage them securely
File servers remain a critical part of many IT environments, but managing access securely can become complex as permissions accumulate. tenfold Software outlines five best practices for simplifying file server administration and maintaining least-privilege access. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/file-servers-are-here-to-stay-heres-how-to-manage-them-securely/)
The Hacker News
Aug 31, 2026
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
The boring parts caused most of the trouble.
A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional.
Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept
[Read full article on The Hacker News](https://thehackernews.com/2026/08/weekly-recap-chinese-spy-proxy-ai.html)
The Hacker News
Aug 31, 2026
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions.
Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool
[Read full article on The Hacker News](https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html)
The Hacker News
Aug 31, 2026
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security.
The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its
[Read full article on The Hacker News](https://thehackernews.com/2026/08/aurora-ransomware-operators-use-cursor.html)
BleepingComputer
Aug 31, 2026
Microsoft says Windows 11 KB5120998 update resets mouse settings
Microsoft has confirmed that mouse settings are being reverted on Windows 11 systems after installing the KB5120998 August 2026 non-security preview update. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/microsoft-says-windows-11-kb5120998-update-resets-mouse-settings/)
CyberScoop
Aug 31, 2026
The AI Kill Switch Act is repeating the Clipper Chip’s mistakes
Mandating ‘kill switches’ for AI agents would threaten the security of America’s critical infrastructure and undercut U.S. AI leadership. Congress must reject the AI Kill Switch Act.
The post The AI Kill Switch Act is repeating the Clipper Chip’s mistakes appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/ai-kill-switch-act-clipper-chip-mistakes-op-ed/)
BleepingComputer
Aug 31, 2026
Nigerians extradited to US for sextortion, deaths of two teens
Two Nigerian men extradited to the U.S. on Thursday have been charged with involvement in sextortion schemes that resulted in the deaths of two minor victims in Mississippi and North Carolina. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/nigerians-charged-US-over-sextortion-deaths-of-us-teens/)
The Hacker News
Aug 31, 2026
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks.
Sygnia, the incident response firm that investigated the intrusion, said the actor
[Read full article on The Hacker News](https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html)
BleepingComputer
Aug 31, 2026
Microsoft asks users to ignore 'Antivirus is turned off' errors
Microsoft asked customers this week to ignore alerts that Defender Antivirus has been turned off after installing the latest Defender updates. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-asks-users-to-ignore-antivirus-is-turned-off-errors/)
The Hacker News
Aug 31, 2026
DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted.
Last week, the DoJ said the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department
[Read full article on The Hacker News](https://thehackernews.com/2026/08/doj-corrects-china-hacking-claim-says.html)
BleepingComputer
Aug 30, 2026
FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
FulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclosed. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/)
BleepingComputer
Aug 30, 2026
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/)
BleepingComputer
Aug 30, 2026
Chrome Web Store extensions caught stealing crypto, browser data
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/)
The Hacker News
Aug 30, 2026
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell.
\"While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex
[Read full article on The Hacker News](https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html)
BleepingComputer
Aug 29, 2026
Anthropic is cutting Claude Code's current weekly limits by 17%
Anthropic is permanently increasing Claude Code's standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, but it's not as good as it sounds. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-is-cutting-claude-codes-current-weekly-limits-by-17-percent/)
BleepingComputer
Aug 29, 2026
Brave browser adds email aliases to help users evade tracking
The latest version of the Brave browser, 1.94, introduces a feature called 'Email Aliases' that allows users to generate disposable email addresses when signing up to a new service. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/brave-browser-adds-email-aliases-to-help-users-evade-tracking/)
BleepingComputer
Aug 28, 2026
McKesson discloses breach after ShinyHunters claims patient data theft
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/)
The Hacker News
Aug 28, 2026
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands.
The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment
[Read full article on The Hacker News](https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html)
CyberScoop
Aug 28, 2026
ATF confirms cyberattack hit system containing info on its investigation targets
The prolific ransomware group Qilin claimed responsibility for the attack. ATF insists the incident was limited to a standalone system and hasn’t impacted critical operations.
The post ATF confirms cyberattack hit system containing info on its investigation targets appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/atf-doj-cyberattack-qilin-ransomware/)
BleepingComputer
Aug 28, 2026
68-year-old imprisoned after making $1.3 million by pirating IPTV services
A 68-year-old has been sentenced in the U.K. to more than six years in prison for operating an illegal IPTV (Internet Protocol Television) service that generated £980,812 ($1.3 million) over three years. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/68-year-old-imprisoned-after-making-13-million-by-pirating-iptv-services/)
The Hacker News
Aug 28, 2026
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks.
Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting.
\"This new privacy standard works in tandem
[Read full article on The Hacker News](https://thehackernews.com/2026/08/android-17-adds-os-wide-ech-to-hide.html)
The Hacker News
Aug 28, 2026
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities.
The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active
[Read full article on The Hacker News](https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html)
BleepingComputer
Aug 28, 2026
Toy-making giant Hasbro disclose data breach affecting employees
Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/toy-making-giant-hasbro-disclose-data-breach-affecting-employees/)
BleepingComputer
Aug 27, 2026
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/nearly-700-rogue-ai-agents-coordinated-in-the-hugging-face-attack/)
The Hacker News
Aug 27, 2026
OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May.
The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a \"highly capable
[Read full article on The Hacker News](https://thehackernews.com/2026/08/openai-says-reward-hacking-drove-ai.html)
CyberScoop
Aug 27, 2026
Unit 42 warns AI has shifted balance of power from defenders to attackers
Palo Alto Networks’ threat intelligence team said the early waves of threats riding on agentic AI models have broken in the wild, and organizations are unprepared for what’s coming next.
The post Unit 42 warns AI has shifted balance of power from defenders to attackers appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/unit-42-palo-alto-networks-warning-agentic-ai-frontier-models/)
CyberScoop
Aug 27, 2026
100-plus companies call for ‘global surge’ in AI-powered cyber defense
OpenAI, Anthropic, Google, Microsoft, and others say there’s a narrow “defenders’ window” to strengthen security before AI-powered attacks become more sophisticated.
The post 100-plus companies call for ‘global surge’ in AI-powered cyber defense appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/ai-cyber-defense-global-surge/)
BleepingComputer
Aug 27, 2026
Manchester Airports Group says hackers stole travelers' data
The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/manchester-airports-group-says-hackers-stole-travelers-data/)
The Hacker News
Aug 27, 2026
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine.
The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different
[Read full article on The Hacker News](https://thehackernews.com/2026/08/threatsday-296k-iot-botnet-100-water.html)
CyberScoop
Aug 27, 2026
Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos
The two men face 14 charges combined. Private researchers traced one suspect through leaked passwords and a decade-old gaming profile.
The post Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/teampcp-cybercrime-arrests-supply-chain-attacks/)
BleepingComputer
Aug 27, 2026
How Threat Research and MDR Help SMBs Build a Defensive Edge
Threat research gives security teams insight into how attackers operate, while MDR turns that intelligence into faster detection and response. ESET explains how combining threat intelligence, continuous monitoring, and human expertise can help SMBs strengthen their defenses. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/how-threat-research-and-mdr-help-smbs-build-a-defensive-edge/)
BleepingComputer
Aug 27, 2026
Android 17 adds ECH support to make web browsing harder to track
Google is introducing new network security protections in Android 17 to strengthen connection privacy, address cellular vulnerabilities, and protect the privacy of users' home networks. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/android-17-adds-ech-support-to-make-web-browsing-harder-to-track/)
BleepingComputer
Aug 27, 2026
Australia arrests alleged TeamPCP hackers behind supply-chain attacks
Australian authorities have arrested and charged two young men accused of being part of the TeamPCP hacking group linked to a string of far-reaching developer supply chain attacks. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/australia-arrests-alleged-teampcp-hackers-behind-supply-chain-attacks/)
The Hacker News
Aug 27, 2026
Learn How to Build Security Operations Ready for AI-Powered Attacks
Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act.
Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security processes were built to handle.
The challenge is no longer just finding another vulnerability or
[Read full article on The Hacker News](https://thehackernews.com/2026/08/learn-how-to-build-security-operations.html)
The Hacker News
Aug 27, 2026
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela.
GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control
[Read full article on The Hacker News](https://thehackernews.com/2026/08/gocaracal-malware-uses-ethereum-smart.html)
The Hacker News
Aug 27, 2026
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell.
Dubbed GPUThor, the attack was developed by researchers at the University of Toronto, who hammered four DRAM
[Read full article on The Hacker News](https://thehackernews.com/2026/08/gputhor-rowhammer-defeats-ecc-on-nvidia.html)
CyberScoop
Aug 26, 2026
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
The order says any foreign-produced equipment deemed to pose national security risks can’t be purchased or installed.
The post Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/energy-department-cybersecurity-executive-order-rules/)
CyberScoop
Aug 26, 2026
Officials disrupt Chinese espionage operation that hit multiple federal agencies
The full hacking suite, seized by authorities, allowed Chinese government funded attackers to intrude highly sensitive networks undetected for more than eight years.
The post Officials disrupt Chinese espionage operation that hit multiple federal agencies appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/qtfy-china-espionage-group-infrastructure-seized/)
CyberScoop
Aug 26, 2026
OpenAI: Agent behavior that led to Hugging Face intrusion formed in May
The company says the breach stemmed from a systemic failure of alignment and security, and has taken measures to prevent agents from independently orchestrating complex cyberattacks.
The post OpenAI: Agent behavior that led to Hugging Face intrusion formed in May appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/openai-hugging-face-agent-breach-report/)
BleepingComputer
Aug 26, 2026
New GPUThor attack defeats NVIDIA ECC protection for root access
A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/new-gputhor-attack-defeats-nvidia-ecc-protection-for-root-access/)
The Hacker News
Aug 26, 2026
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country.
The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).&
[Read full article on The Hacker News](https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html)
BleepingComputer
Aug 26, 2026
Meta agrees to $18 billion settlement over teen social media harms
Meta has reached a proposed settlement worth up to approximately $18 billion with a bipartisan coalition of 52 attorneys generals over allegations that Facebook and Instagram were deliberately designed to encourage compulsive use by children and teenagers. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/technology/meta-agrees-to-18-billion-settlement-over-teen-social-media-harms/)
The Hacker News
Aug 26, 2026
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC).
Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka
[Read full article on The Hacker News](https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html)
BleepingComputer
Aug 26, 2026
Boston Scientific says cyberattack disrupted operations globally
Medical technology company Boston Scientific has been targeted in a cyberattack that disrupted some of its IT systems, causing operational disruptions globally. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/boston-scientific-says-cyberattack-disrupted-operations-globally/)
BleepingComputer
Aug 26, 2026
Hackers target Microsoft SharePoint RCE chain with PoC exploit
Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/)
BleepingComputer
Aug 26, 2026
FBI disrupts proxy network enabling Chinese espionage operations
The FBI has disrupted infrastructure associated with a technical \"quartermaster\" that provided reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/fbi-disrupts-proxy-network-enabling-chinese-espionage-operations/)
BleepingComputer
Aug 26, 2026
Snowflake ends service-account passwords. Now comes the hard part
Snowflake is ending password authentication for legacy service accounts, forcing organizations to migrate them to passwordless methods. Token Security explains why the harder challenge is identifying what uses each account, who owns it, and how much access it still needs. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/snowflake-ends-service-account-passwords-now-comes-the-hard-part/)
The Hacker News
Aug 26, 2026
NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process.
In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-based phishing platform that
[Read full article on The Hacker News](https://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html)
CyberScoop
Aug 26, 2026
Election official says Tina Peters would be consultant, won’t have access to election systems
Shasta County registrar Clint Curtis told CyberScoop he needs Peters to help manage the county’s 2026 elections and he’s not concerned about her past conviction.
The post Election official says Tina Peters would be consultant, won’t have access to election systems appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/shasta-county-election-clint-curtis-tina-peters-controversy/)
BleepingComputer
Aug 26, 2026
Ubiquiti patches three max severity security vulnerabilities
Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-security-vulnerabilities/)
The Hacker News
Aug 26, 2026
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes.
Both organizations were fully compromised at the domain level, and in both, the red team also
[Read full article on The Hacker News](https://thehackernews.com/2026/08/cisa-red-team-compromised-two-critical.html)
BleepingComputer
Aug 26, 2026
Microsoft tests new privacy controls for Windows 11 desktop apps
Microsoft has begun testing new privacy controls that will let Windows 11 users choose which desktop applications can access their camera, microphone, and precise location. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-tests-new-privacy-controls-for-windows-11-desktop-apps/)
The Hacker News
Aug 26, 2026
Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine
The SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert arrives; a detection engine assigns a severity score. The issue then waits for a human to decide if it should escalate to an investigation.
Given the volume of
[Read full article on The Hacker News](https://thehackernews.com/2026/08/imagine-soc-without-queue-from-alert.html)
The Hacker News
Aug 26, 2026
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn.
The accounts \"were being used to promote the International Burke Institute (IBI), a
[Read full article on The Hacker News](https://thehackernews.com/2026/08/openai-bans-russian-chatgpt-accounts.html)
The Hacker News
Aug 26, 2026
INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown
An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects.
\"The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks – such as the Black Axe and other similar groups,\" INTERPOL said.
\"These groups are
[Read full article on The Hacker News](https://thehackernews.com/2026/08/interpol-operation-jackal-iv-arrests-58.html)
The Hacker News
Aug 26, 2026
Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design.
The sample is an unsigned 64-bit Windows dynamic-link library (DLL) of 59,904 bytes, built to be side-loaded into&
[Read full article on The Hacker News](https://thehackernews.com/2026/08/newly-sleepwalker-backdoor-waits-for.html)
The Hacker News
Aug 26, 2026
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode.
SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures across
[Read full article on The Hacker News](https://thehackernews.com/2026/08/fake-apple-support-ai-calls-target.html)
BleepingComputer
Aug 25, 2026
LACMA data breach last year exposed social security and medical data
The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/lacma-data-breach-last-year-exposed-social-security-and-medical-data/)
BleepingComputer
Aug 25, 2026
Hackers abuse npm mirrors to host phishing redirect pages
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages/)
CyberScoop
Aug 25, 2026
The GTA VI leaks are breaking the internet. Security researchers have seen this before.
A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience.
The post The GTA VI leaks are breaking the internet. Security researchers have seen this before. appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/grand-theft-auto-6-data-theft-extortion-leaks/)
BleepingComputer
Aug 25, 2026
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes/)
CyberScoop
Aug 25, 2026
Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice
Joshua Culver, aka “Maverick Young,” is accused of imitating the head of the NSA’s Tailored Access Operations unit during a time it wasn’t called that.
The post Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/arrested-man-allegedly-impersonated-nsa-elite-hacking-unit-supreme-court-chief-justice/)
The Hacker News
Aug 25, 2026
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an \"unprecedented, whole-of-government, economic campaign\" against the nation and its enablers.
\"We are launching an economic onslaught against Iran's financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime
[Read full article on The Hacker News](https://thehackernews.com/2026/08/us-sanctions-iran-linked-hackers-behind.html)
CyberScoop
Aug 25, 2026
Water sector passes, government sector fails attempts to spot and halt simulated CISA attack
Agency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further.
The post Water sector passes, government sector fails attempts to spot and halt simulated CISA attack appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/cisa-red-team-report-government-water-cybersecurity/)
BleepingComputer
Aug 25, 2026
Massive DDoS attack disrupts Norway’s government digital services
A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/massive-ddos-attack-disrupts-norways-government-digital-services/)
BleepingComputer
Aug 25, 2026
Hospital operator Nutex Health says data stolen in cyberattack
Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hospital-operator-nutex-health-says-data-stolen-in-cyberattack/)
CyberScoop
Aug 25, 2026
Interpol targets Black Axe’s illicit financial web in latest international sting
The multi-country sting targeted Black Axe financial networks, seizing millions in assets and uncovering Crime-as-a-Service infrastructure across four continents.
The post Interpol targets Black Axe’s illicit financial web in latest international sting appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/interpol-operation-jackal-iv-black-axe-arrests/)
PortSwigger Research
Aug 25, 2026
What's in a tag name? JavaScript, apparently
I was on my laptop, as I often am when there's rubbish on telly, and found myself wondering what characters are allowed in a tag. I knew they had to begin with \"a-zA-Z\", but what about after that? I t
[Read full article on PortSwigger Research](https://portswigger.net/research/whats-in-a-tag-name-javascript-apparently)
BleepingComputer
Aug 25, 2026
From Fake Workers to Account Recovery: The Growing Identity Verification Risk
Attackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronger identity verification can help organizations prevent fake workers and social engineering attacks from gaining legitimate access. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/from-fake-workers-to-account-recovery-the-growing-identity-verification-risk/)
BleepingComputer
Aug 25, 2026
Microsoft PowerToys adds Alt+Tab-style switching for an app's windows
Microsoft updated its Windows PowerToys toolset with a new utility dubbed \"Window Hopper\" that lets users switch between an app's windows more quickly. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-powertoys-adds-alt-plustab-style-switching-for-an-apps-windows/)
The Hacker News
Aug 25, 2026
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method.
The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023,
[Read full article on The Hacker News](https://thehackernews.com/2026/08/whatsapp-adds-multiple-passkeys-for.html)
BleepingComputer
Aug 25, 2026
WhatsApp adds stronger two-step verification, multiple passkeys
WhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/whatsapp-adds-stronger-two-step-verification-multiple-passkeys/)
BleepingComputer
Aug 25, 2026
Hackers breached over 270 Zimbra servers in ongoing attacks
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-breached-over-270-zimbra-servers-in-ongoing-attacks/)
The Hacker News
Aug 25, 2026
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication.
According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based.
Mirage2FA Campaign
[Read full article on The Hacker News](https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html)
The Hacker News
Aug 25, 2026
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages.
\"While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the
[Read full article on The Hacker News](https://thehackernews.com/2026/08/24-npm-packages-abuse-unpkg-mirrors-to.html)
The Hacker News
Aug 25, 2026
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE.
While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development
[Read full article on The Hacker News](https://thehackernews.com/2026/08/e4del-and-pinhole-rats-turn-ftp-banners.html)
The Hacker News
Aug 25, 2026
Frontier AI: Vulnerability Management's Systemic Revolution
Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful care and feeding from both sides, both sides were aiming to work toward a
[Read full article on The Hacker News](https://thehackernews.com/2026/08/frontier-ai-vulnerability-managements.html)
BleepingComputer
Aug 24, 2026
Hackers target WordPress sites in miniOrange auth bypass attacks
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks/)
CyberScoop
Aug 24, 2026
Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’
It’s a follow-up to an indictment the Justice Department unsealed last week against people affiliated with the Mabna Institute.
The post Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’ appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/us-treasury-sanctions-iranian-hackers-economic-dday/)
CyberScoop
Aug 24, 2026
Bipartisan Senate bill aims to prepare energy sector for Q-Day
Under the bill, FERC would consider cyber threats from quantum computers and post-quantum cryptography in its reliability standards for the energy sector.
The post Bipartisan Senate bill aims to prepare energy sector for Q-Day appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/quantum-guard-act-electric-grid-cybersecurity/)
BleepingComputer
Aug 24, 2026
TikTok reaches $400M settlement with US over COPPA violations
The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/legal/tiktok-reaches-400m-settlement-with-us-over-coppa-violations/)
The Hacker News
Aug 24, 2026
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients.
McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs,
[Read full article on The Hacker News](https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html)
BleepingComputer
Aug 24, 2026
ReliaQuest confirms failed data-theft attack after ShinyHunters breach
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/)
The Hacker News
Aug 24, 2026
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet.
That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are.
Plenty to clean up. Here’s the short version.
⚡ Threat of the Week
U.S.
[Read full article on The Hacker News](https://thehackernews.com/2026/08/weekly-recap-ai-powered-plc-attacks.html)
BleepingComputer
Aug 24, 2026
Microsoft Teams now lets admins block external bots from meetings
Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/microsoft-teams-now-lets-admins-block-external-bots-from-meetings/)
BleepingComputer
Aug 24, 2026
South Korean startup platform breach exposes key management failures
A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/south-korean-startup-platform-breach-exposes-key-management-failures/)
BleepingComputer
Aug 24, 2026
Microsoft: August updates break printing, PDF export in WPF apps
Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in WPF applications. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-august-updates-break-printing-pdf-export-in-wpf-apps/)
The Hacker News
Aug 24, 2026
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups.
According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha)
[Read full article on The Hacker News](https://thehackernews.com/2026/08/wordlistloader-delivers-amatera-via.html)
The Hacker News
Aug 24, 2026
Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt
If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work.
The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never built to handle. More dependencies mean more vulnerabilities to review, more remediation work, and a backlog that can
[Read full article on The Hacker News](https://thehackernews.com/2026/08/shipping-more-ai-code-than-you-can.html)
The Hacker News
Aug 24, 2026
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent.
The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs. The activity is assessed to be the work of a China-nexus threat actor with moderate
[Read full article on The Hacker News](https://thehackernews.com/2026/08/operation-quicsilver-targets-myanmar.html)
The Hacker News
Aug 24, 2026
The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of AI super-adopters who are quietly hardcoding unvetted tools into critical business operations.
According to new research published by Akamai, the top 5% of enterprise power
[Read full article on The Hacker News](https://thehackernews.com/2026/08/the-outsized-shadow-why-5-of-ai-users.html)
BleepingComputer
Aug 24, 2026
Microsoft shares temporary fix for Windows 11 gaming issues
Microsoft has shared a temporary fix for ongoing gaming issues caused by Windows 11 updates released during the August 2026 Patch Tuesday. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-temporary-fix-for-windows-11-gaming-issues/)
The Hacker News
Aug 24, 2026
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.
The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open
[Read full article on The Hacker News](https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html)
BleepingComputer
Aug 23, 2026
ToxicPanda Android malware uses VPN permissions to block Google Play
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/)
CyberScoop
Aug 22, 2026
Postal Service moves to finalize mail ballot regs before SCOTUS ruling
The rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision.
The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/postal-service-finalizes-mail-in-ballot-rules-before-scotus-ruling/)
BleepingComputer
Aug 22, 2026
Hackers infect Android car head units with proxy botnet malware
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/)
BleepingComputer
Aug 22, 2026
Named Pipes Under Attack: Securing Windows Interprocess Communication
Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe communication. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/named-pipes-under-attack-securing-windows-interprocess-communication/)
CyberScoop
Aug 21, 2026
Apollo discloses data breach from ongoing wave of attacks hitting financial sector
The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data.
The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/)
The Hacker News
Aug 21, 2026
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0.
\"When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process,\" TrendAI, Trend Micro's
[Read full article on The Hacker News](https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html)
BleepingComputer
Aug 21, 2026
New SynkLoader malware pushed in Microsoft Teams phishing campaign
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/)
BleepingComputer
Aug 21, 2026
Hundreds of leaked AWS keys give full control over corporate accounts
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/)
The Hacker News
Aug 21, 2026
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.
Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet.
\"The malware spread through the built-in updaters of
[Read full article on The Hacker News](https://thehackernews.com/2026/08/android-car-malware-spreads-through.html)
BleepingComputer
Aug 21, 2026
Microsoft blames Windows gaming issues on RGB lighting devices
Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-blames-windows-gaming-issues-on-rgb-lighting-devices/)
BleepingComputer
Aug 21, 2026
Is Online Privacy Possible? How Digital Identities Can Help
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spam, and identity theft. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/is-online-privacy-possible-how-digital-identities-can-help/)
BleepingComputer
Aug 21, 2026
Microsoft rolls out Classic Outlook theme for New Outlook users
Microsoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-rolls-out-classic-outlook-theme-for-new-outlook-users/)
The Hacker News
Aug 21, 2026
Wazuh and AI For Enhanced SOC Workflows
Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden within large datasets, and support faster decision-making. Cybersecurity has experienced a similar transformation. While attackers employ AI to automate
[Read full article on The Hacker News](https://thehackernews.com/2026/08/wazuh-and-ai-for-enhanced-soc-workflows.html)
BleepingComputer
Aug 21, 2026
Hackers abuse FTP server banners to deliver new Windows malware
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/)
The Hacker News
Aug 20, 2026
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation.
The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner
[Read full article on The Hacker News](https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html)
The Hacker News
Aug 20, 2026
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S.
These clusters include UNC6293, UNC7005, and UNC5976.
\"These clusters engage in persistent, adaptive
[Read full article on The Hacker News](https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html)
CyberScoop
Aug 20, 2026
Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist
Kyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting.
The post Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/764-member-sentenced-longest-prison-sentence-kyle-spitze/)
BleepingComputer
Aug 20, 2026
Hackers poison arrayref Rust crate to push infostealer malware
Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/)
The Hacker News
Aug 20, 2026
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.
Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort needed to cause damage.
Nothing here needs
[Read full article on The Hacker News](https://thehackernews.com/2026/08/threatsday-gogs-100-rce-n8n-workflow-to.html)
The Hacker News
Aug 20, 2026
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
The U.S. government on Wednesday warned of an \"active threat\" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts.
The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and capability development using AI-generated scripts disguised as legitimate monitoring tools. That
[Read full article on The Hacker News](https://thehackernews.com/2026/08/ai-generated-exploit-scripts-target.html)
CyberScoop
Aug 20, 2026
Retail theft bill spurs ‘very large and very dangerous’ surveillance fears
The Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate — and supporters say it could help fight cybercrime.
The post Retail theft bill spurs ‘very large and very dangerous’ surveillance fears appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/corca-retail-theft-bill-ice-surveillance/)
BleepingComputer
Aug 20, 2026
Critical Elementor Pro bug exposes WordPress sites to RCE attacks
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/)
The Hacker News
Aug 20, 2026
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page.
The AI security company, which has codenamed the technique \"Cryptographic Context Injection,\" said the
[Read full article on The Hacker News](https://thehackernews.com/2026/08/new-cryptographic-context-injection.html)
BleepingComputer
Aug 20, 2026
How MSPs can catch phishing attacks email filters miss
AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attacks that make it past the inbox. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/how-msps-can-catch-phishing-attacks-email-filters-miss/)
CyberScoop
Aug 20, 2026
The push to designate AI as the next critical infrastructure sector
The designation would unlock a range of federal services, tools and resources for an industry that policymakers view as increasingly tied to national and economic security.
The post The push to designate AI as the next critical infrastructure sector appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/ai-critical-infrastructure-designation-cisa-report/)
The Hacker News
Aug 20, 2026
Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale (POS) terminal reads over near-field communication (NFC), without breaking any of the card's cryptography.
The attack, which the researchers named \"Zombie Card,\" requires physical
[Read full article on The Hacker News](https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html)
The Hacker News
Aug 20, 2026
Why "Shady AI" is Security's Next Big Governance Problem
In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it.
The incident began when a Meta employee posted a technical question on an internal forum. An engineer used an approved AI agent to analyze it, but the agent posted its response publicly without approval. The employee
[Read full article on The Hacker News](https://thehackernews.com/2026/08/why-shady-ai-is-securitys-next-big.html)
The Hacker News
Aug 20, 2026
CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up to 350x against the origin server.
The attacks, collectively named \"CDN Tsunami,\" were evaluated against Alibaba, Baidu,
[Read full article on The Hacker News](https://thehackernews.com/2026/08/cdn-tsunami-attack-abuses-http3.html)
The Hacker News
Aug 20, 2026
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications.
\"Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud
[Read full article on The Hacker News](https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html)
BleepingComputer
Aug 20, 2026
CISA warns of hackers exploiting critical MLflow vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-mlflow-vulnerability/)
The Hacker News
Aug 20, 2026
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with \"significant enhancements,\" including a set of 167 remote commands and expands its targeting footprint globally.
Zimperium zLabs, in a Wednesday report, said the Android malware also features a PIN harvesting workflow targeting more than 140 banking and cryptocurrency applications.
[Read full article on The Hacker News](https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html)
BleepingComputer
Aug 20, 2026
New Manic Android malware can exfiltrate data through nearby devices
A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/)
The Hacker News
Aug 20, 2026
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products.
According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed Offside Wallet Theft Factory, is believed to
[Read full article on The Hacker News](https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html)
BleepingComputer
Aug 20, 2026
Microsoft says August Windows updates may cause gaming issues
Microsoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-august-windows-updates-may-cause-gaming-issues-reboots/)
BleepingComputer
Aug 20, 2026
OpenAI confirms ChatGPT is down as logins and signups fail
ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/artificial-intelligence/openai-confirms-chatgpt-is-down-as-logins-and-signups-fail/)
BleepingComputer
Aug 19, 2026
Rogue ransomware affiliate poses as data recovery firm to steal payments
A suspected ransomware affiliate is posing as a ransomware recovery service called \"Ransom Busters,\" contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-data-recovery-firm/)
BleepingComputer
Aug 19, 2026
Rogue ransomware affiliate poses as recovery firm to steal payments
A suspected ransomware affiliate is posing as a ransomware recovery service called \"Ransom Busters,\" contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/)
BleepingComputer
Aug 19, 2026
Sakura Internet hack exposes data of up to 1.36 million accounts
Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/sakura-internet-hack-exposes-data-of-up-to-136-million-accounts/)
BleepingComputer
Aug 19, 2026
Healthtech firm CareCloud data breach impacts 3.7 million patients
U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breach-impacts-37-million-patients/)
The Hacker News
Aug 19, 2026
Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021.
The end-to-end experiment used an attacker Worker and a victim Worker controlled by the researchers,
[Read full article on The Hacker News](https://thehackernews.com/2026/08/cloudflare-workers-spectre-attack-leaks.html)
CyberScoop
Aug 19, 2026
AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn
The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first.
The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/hackers-use-ai-target-siemens-plcs-critical-infrastructure/)
BleepingComputer
Aug 19, 2026
Hackers compromise 14,500 Dahua web cameras in 35-day campaign
In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-compromise-14-500-dahua-web-cameras-in-35-day-campaign/)
The Hacker News
Aug 19, 2026
OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior
OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert another Hugging Face-like incident.
\"As models become more capable, the risks associated with developing and testing them internally also grow,\" the AI company
[Read full article on The Hacker News](https://thehackernews.com/2026/08/openai-pauses-frontier-rl-training-as.html)
BleepingComputer
Aug 19, 2026
US warns of AI-powered attacks on Siemens PLCs in critical infrastructure
U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-infrastructure/)
CyberScoop
Aug 19, 2026
A California county wants to hire Tina Peters to help run its elections
After her prison sentence for felony election-related crimes was commuted, Peters is poised to once again administer critical election duties.
The post A California county wants to hire Tina Peters to help run its elections appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/shasta-county-elections-tina-peters/)
BleepingComputer
Aug 19, 2026
US charges Iranian hackers over $3.4 billion intellectual property theft
The U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/us-charges-iranian-hackers-over-34-billion-intellectual-property-theft/)
CyberScoop
Aug 19, 2026
The long tail of Clop’s PTC hack is just beginning to emerge
The data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims.
The post The long tail of Clop’s PTC hack is just beginning to emerge appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/clop-zero-day-attacks-ptc-windchill-flexplm/)
BleepingComputer
Aug 19, 2026
Password spraying attacks surge 155x as hackers exploit MFA gaps
Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies that left some login flows unprotected. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/password-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps/)
The Hacker News
Aug 19, 2026
SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia.
The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. SilkParasite, first discovered in late 2025, is assessed to be a
[Read full article on The Hacker News](https://thehackernews.com/2026/08/silkparasite-espionage-campaign-targets.html)
The Hacker News
Aug 19, 2026
Phishing 3.0: The Fight Moves to Agent Versus Agent
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing now that the sender is no longer a person.
From Bad Content to Bad Intent to AI on Both Sides
Phishing 1.0 was bad
[Read full article on The Hacker News](https://thehackernews.com/2026/08/phishing-30-fight-moves-to-agent-versus.html)
The Hacker News
Aug 19, 2026
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity.
\"The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software
[Read full article on The Hacker News](https://thehackernews.com/2026/08/stopandprotect-uses-nearly-2000-hacked.html)
BleepingComputer
Aug 19, 2026
Microsoft fixes known issue causing Windows Defender crashes
Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-known-issue-causing-windows-defender-crashes/)
BleepingComputer
Aug 19, 2026
Windows 11 24H2 Home and Pro reach end of support in 2 months
Microsoft has reminded customers that systems running Home and Pro editions of Windows 11 24H2 will stop receiving updates in two months. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/windows-11-24h2-home-and-pro-reach-end-of-support-in-2-months/)
BleepingComputer
Aug 19, 2026
CISA: Medusa ransomware hit over 500 critical infrastructure orgs
The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/cisa-medusa-ransomware-hit-over-500-critical-infrastructure-orgs/)
The Hacker News
Aug 19, 2026
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration.
The tech giant said it required multiple endpoint and network behaviors to align before
[Read full article on The Hacker News](https://thehackernews.com/2026/08/microsoft-links-30-rotating-domains-to.html)
BleepingComputer
Aug 18, 2026
Comcast turns your Xfinity WiFi into a home motion detector
Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/comcast-turns-your-xfinity-wifi-into-a-home-motion-detector/)
CyberScoop
Aug 18, 2026
Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute
The superseding indictment adds defendants and allegations against the Iranian firm accused of a massive cybertheft campaign against foreign universities and others.
The post Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/mabna-institute-iranian-hackers-indictment/)
BleepingComputer
Aug 18, 2026
Clop created custom web shell for Windchill data theft attacks
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/clop-created-custom-web-shell-for-windchill-data-theft-attacks/)
CyberScoop
Aug 18, 2026
Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
The updated warning from the FBI, CISA and HHS draws on a year’s worth of investigations to detail how the group gains initial access and what it does afterward.
The post Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/medusa-ransomware-tactics-cisa-advisory/)
The Hacker News
Aug 18, 2026
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000.
\"In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous,\" GuidePoint Research
[Read full article on The Hacker News](https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html)
BleepingComputer
Aug 18, 2026
Your Controls Block Known Attacks. What About the Behavior?
Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security's Blue Report 2026 shows how prevention rates can vary dramatically by technique and why behavioral testing is needed to uncover those gaps. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/your-controls-block-known-attacks-what-about-the-behavior/)
The Hacker News
Aug 18, 2026
AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions.
The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent coding
[Read full article on The Hacker News](https://thehackernews.com/2026/08/ai-mind-viruses-can-spread-between.html)
The Hacker News
Aug 18, 2026
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT.
\"TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services,\" Ontinue said in a technical report shared with The Hacker News. \"Tasking flows through SharePoint Online file
[Read full article on The Hacker News](https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.html)
The Hacker News
Aug 18, 2026
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer.
OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below -
ubnuler
ubnlder
ri18nr
reaker
rakier
orakw
joxn
[Read full article on The Hacker News](https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.html)
The Hacker News
Aug 18, 2026
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco.
The activity, which Reco has named the City Forum campaign after a domain tied to the attacker's IP address, traces back to one server: 158.220.87.79, hosted on a
[Read full article on The Hacker News](https://thehackernews.com/2026/08/one-attacker-has-scraped-both.html)
BleepingComputer
Aug 18, 2026
Microsoft tests faster Windows File Explorer, new context menu
Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-tests-faster-windows-explorer-customizable-context-menu/)
BleepingComputer
Aug 18, 2026
Microsoft confirms outage affecting search in Microsoft 365 apps
Microsoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-bug-behind-microsoft-365-search-issues/)
BleepingComputer
Aug 18, 2026
Microsoft starts removing WMIC tool used by cybercriminals
Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-wmic-lolbin-tool-in-windows-11-beta-builds/)
CyberScoop
Aug 17, 2026
Details emerge on BlackFile’s recent attacks on financial companies
BlackFile’s four affiliate groups are still targeting victims, including medical technology organizations. Several potential victims received new extortion demands last week, according to Google.
The post Details emerge on BlackFile’s recent attacks on financial companies appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/blackfile-cyberattacks-financial-sector/)
CyberScoop
Aug 17, 2026
Irregular says ‘human oversight’ responsible for AI sandbox escape incidents
In a post-mortem, the frontier AI testing company said internet access for models is necessary to fully test out their cybersecurity capabilities.
The post Irregular says ‘human oversight’ responsible for AI sandbox escape incidents appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/irregular-ai-sandbox-escape-human-oversight/)
BleepingComputer
Aug 17, 2026
Hacker claims 3.6 million Azure account records stolen from major companies
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/)
BleepingComputer
Aug 17, 2026
Pokémon Center data breach exposes customer info, cancels some orders
Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/)
The Hacker News
Aug 17, 2026
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel.
Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the
[Read full article on The Hacker News](https://thehackernews.com/2026/08/cavern-c2-uses-dns-and-google-apps.html)
BleepingComputer
Aug 17, 2026
Microsoft confirms GitHub is down worldwide
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-github-is-down-worldwide/)
BleepingComputer
Aug 17, 2026
Certighost and the Privilege Hiding in Your Certificate Authority
CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/certighost-and-the-privilege-hiding-in-your-certificate-authority/)
The Hacker News
Aug 17, 2026
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
The expensive attacks are not always the clever ones.
This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely.
So, nothing magical. Just a
[Read full article on The Hacker News](https://thehackernews.com/2026/08/weekly-recap-vmware-exploits-windows-0.html)
BleepingComputer
Aug 17, 2026
Windows Server 2022 reaches end of mainstream support in 60 days
Microsoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-mainstream-support-in-60-days/)
The Hacker News
Aug 17, 2026
How MCP Servers Can Expose Enterprise Secrets
MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their systems, that exposure can silently become a major gap in MCP server security. The Model Context Protocol (MCP) allows AI agents to reach the tools and data,
[Read full article on The Hacker News](https://thehackernews.com/2026/08/how-mcp-servers-can-expose-enterprise.html)
BleepingComputer
Aug 17, 2026
Philips and GE investigating Clop ransomware data theft claims
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/)
The Hacker News
Aug 17, 2026
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker.
The advisory, published August 17, 2026, is the second stage of a chain that began in March 2026, when SSD disclosed remote code execution in the
[Read full article on The Hacker News](https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html)
BleepingComputer
Aug 17, 2026
French tax authority data breach affects 678,000 individuals
The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/french-tax-authority-data-breach-affects-678-000-individuals/)
BleepingComputer
Aug 17, 2026
Microsoft working on Defender patch for ShieldBreak zero-day
Microsoft is working on a security patch for the \"ShieldBreak\" zero-day vulnerability disclosed last week by security researcher \"Nightmare Eclipse\" and now tracked as CVE-2026-69414. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/microsoft-working-on-defender-patch-for-shieldbreak-zero-day/)
BleepingComputer
Aug 16, 2026
Anthropic confirms Claude is down in major outage affecting multiple services
Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-confirms-claude-is-down-in-major-outage-affecting-multiple-services/)
BleepingComputer
Aug 16, 2026
Large-scale DDoS attacks disrupted Threema secure messaging service
Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/large-scale-ddos-attacks-disrupted-threema-secure-messaging-service/)
BleepingComputer
Aug 16, 2026
New AmnesiaStealer macOS malware hijacks browser sessions via remote control
A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/)
BleepingComputer
Aug 15, 2026
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/)
The Hacker News
Aug 15, 2026
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts.
The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It relates to an instance of insufficient authorization checks and input validation.
\"SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit
[Read full article on The Hacker News](https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html)
BleepingComputer
Aug 14, 2026
How Anthropic plans to watermark Claude's AI-generated text
It could soon become easier to identify AI-generated content, even if it's not the usual \"It's Not X, it's Y\" type of post you'd come across on LinkedIn and other socials. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/artificial-intelligence/how-anthropic-plans-to-watermark-claudes-ai-generated-text/)
The Hacker News
Aug 14, 2026
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale.
DNS threat intelligence firm Infoblox has given the name dropcatch domains to those that get a second chance, where an expired domain becomes available for registration and is then snapped up by another party.
During the first half of 2026, 50,400
[Read full article on The Hacker News](https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html)
BleepingComputer
Aug 14, 2026
The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/the-modern-attack-chain-rethinking-google-workspace-security-in-the-age-of-ai/)
BleepingComputer
Aug 14, 2026
Shell investigates 'potential incident' after Clop data theft claims
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/shell-investigates-potential-incident-after-clop-data-theft-claims/)
BleepingComputer
Aug 14, 2026
RingCentral data breach exposed info of 1.6 million accounts
The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/)
BleepingComputer
Aug 14, 2026
Data analyst sent to prison for stealing data, extorting employer
A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/data-analyst-sent-to-prison-for-stealing-data-extorting-employer/)
BleepingComputer
Aug 14, 2026
Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks
You're not alone if you just received an \"Apple Threat Notification\" saying it detected a \"mercenary spyware attack targeted at your iPhone.\" [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/apple/apple-sends-new-threat-notification-alerts-over-mercenary-spyware-attacks/)
CyberScoop
Aug 13, 2026
A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo.
The “philosophical shift” that the memo authorizes raises legal, practical and moral questions, experts say.
The post A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo. appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/private-sector-hacking-presidential-memo-cybersecurity/)
CyberScoop
Aug 13, 2026
Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack
Cameron Curry stole corporate data and employee information, which he used to threaten the company as his six-month contract gig came to a close. He ultimately extorted the company for $7,540.92.
The post Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/cameron-curry-insider-attack-brightly-software-sentenced/)
BleepingComputer
Aug 13, 2026
Ukraine shuts down 94 fraudulent call centers, seize millions in cash
Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/ukraine-shuts-down-94-fraudulent-call-centers-seize-millions-in-cash/)
BleepingComputer
Aug 13, 2026
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail-to-encrypt/)
BleepingComputer
Aug 13, 2026
Hackers breach govt webmail while running parallel crypto fraud
The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-breach-govt-webmail-while-running-parallel-crypto-fraud/)
BleepingComputer
Aug 13, 2026
Microsoft patches LegacyHive Windows zero-day vulnerability
Microsoft has released security patches to address a Windows zero-day vulnerability known as \"LegacyHive,\" disclosed after the July 2026 Patch Tuesday. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-legacyhive-windows-zero-day-vulnerability/)
BleepingComputer
Aug 13, 2026
AI 'watermark removers' flood the web. Almost none can prove they work.
Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims about defeating the text watermark can be verified, as Anthropic has not released a detector. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/ai-watermark-removers-flood-the-web-almost-none-can-prove-they-work/)
CyberScoop
Aug 13, 2026
AI’s ‘middle class’ has gotten dramatically better at hacking
As frontier models and their sandbox escaping exploits dominate front-page news, researchers are increasingly worried about cheaper, more efficient AI models.
The post AI’s ‘middle class’ has gotten dramatically better at hacking appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/mid-tier-ai-models-hacking-threat/)
BleepingComputer
Aug 13, 2026
Trezor discloses data breach affecting nearly 14,000 customers
Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping provider and logistics partner, got hacked. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/)
BleepingComputer
Aug 13, 2026
Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion
AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/who-vets-ais-code-the-scale-challenge-facing-open-source-ingestion/)
BleepingComputer
Aug 13, 2026
White House taps security firms for offensive hack-back operations
A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/white-house-taps-security-firms-for-offensive-hack-back-operations/)
BleepingComputer
Aug 13, 2026
WhatsApp rolls out new feature that flags potential scam messages
WhatsApp has begun rolling out a new optional \"Scam Alert\" feature, which uses a local machine learning model to warn users when scammers are targeting them. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/whatsapp-rolls-out-new-feature-that-flags-potential-scam-messages/)
CyberScoop
Aug 13, 2026
Trump turns to private sector in offensive hacking operations memo
One expert called it a “pretty big shift in U.S. cyber policy,” and there have been reservations in the past about opening the door to private sector involvement in cyber offense.
The post Trump turns to private sector in offensive hacking operations memo appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/trump-memo-private-sector-offensive-hacking/)
The Hacker News
Aug 13, 2026
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code.
The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates.
\"The authentication
[Read full article on The Hacker News](https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html)
BleepingComputer
Aug 12, 2026
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/city-forum-data-theft-attacks-target-salesforce-servicenow-portals/)
BleepingComputer
Aug 12, 2026
Android malware combo takes out loans and relays victims' credit cards
A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards/)
BleepingComputer
Aug 12, 2026
Hundreds of fake Chrome VPN extensions route traffic through a proxy
More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hundreds-of-fake-chrome-vpn-extensions-route-traffic-through-a-proxy/)
CyberScoop
Aug 12, 2026
Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan
Israeli cyber firm Dream said the framework adapted mid-operation, corrected its mistakes and expanded as it went along.
The post Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/near-autonomous-ai-attack-government-target-taiwan/)
BleepingComputer
Aug 12, 2026
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Security researchers have disclosed new \"Plug and Pwn\" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/plug-and-pwn-attack-uses-fake-usb-devices-for-windows-system-access/)
BleepingComputer
Aug 12, 2026
Lazarus hackers exploited Windows zero-day to target defense firms
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/lazarus-hackers-exploited-windows-zero-day-to-target-defense-firms/)
BleepingComputer
Aug 12, 2026
FBI: Hackers target online accounts to steal nude photos
The FBI warns that cybercriminals are targeting adults' and children's social media and other online accounts to steal sexually explicit images or videos. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/fbi-warns-of-hackers-targeting-online-accounts-to-steal-explicit-photos/)
The Hacker News
Aug 12, 2026
737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure.
The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66
[Read full article on The Hacker News](https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html)
BleepingComputer
Aug 12, 2026
The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In
Fake remote workers can exploit gaps between hiring checks, device delivery, and account access to enter organizations under false identities. Specops Software explains how document verification and biometric liveness checks can help organizations confirm that the person receiving access is the legitimate new hire. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/the-threat-hiding-in-your-hiring-process-how-fake-remote-workers-get-in/)
BleepingComputer
Aug 12, 2026
Hackers leverage new Microsoft SharePoint exploit in attacks
Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/)
The Hacker News
Aug 12, 2026
Enterprise Defenses Recovered at the Edge and Collapsed Inside
Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none.
According to Picus Labs' new Blue Report 2026, which measured more than 338 million real attack simulations across actual client production environments in the first half of 2026, defenses are having one of their strongest years yet. Average prevention effectiveness
[Read full article on The Hacker News](https://thehackernews.com/2026/08/enterprise-defenses-recovered-at-edge.html)
BleepingComputer
Aug 12, 2026
Signal adds new security feature to thwart man-in-the-middle attacks
Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/signal-adds-new-security-feature-to-thwart-man-in-the-middle-attacks/)
BleepingComputer
Aug 12, 2026
New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named \"ShieldBreak\" after Microsoft released the August 2026 Patch Tuesday security updates. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldbreak-zero-day-grants-system-privileges/)
The Hacker News
Aug 12, 2026
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them.
Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more
[Read full article on The Hacker News](https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html)
The Hacker News
Aug 12, 2026
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak.
The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePlanet.
RoguePlanet has been described
[Read full article on The Hacker News](https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html)
BleepingComputer
Aug 12, 2026
Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
Google says Chrome's anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/google-says-chrome-cuts-7-billion-unwanted-android-notifications-a-day-to-fight-abuse/)
CyberScoop
Aug 12, 2026
Kimwolf botnet rebuilt to survive takedowns, researchers say
Months after police seized its servers and arrested an alleged operator, the Kimwolf botnet is running code that disguises attacks as Chrome traffic and fetches its orders from the Ethereum blockchain.
The post Kimwolf botnet rebuilt to survive takedowns, researchers say appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/kimwolf-botnet-palo-alto-unit-42-android-tv-boxes/)
CyberScoop
Aug 11, 2026
Federal judge issues second order blocking Trump mail-in voting directive
The U.S. Supreme Court temporarily reversed an earlier decision through the shadow docket.
The post Federal judge issues second order blocking Trump mail-in voting directive appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/federal-judge-blocks-trump-mail-in-voting-executive-order/)
BleepingComputer
Aug 11, 2026
DeadLock ransomware uses blockchain to resist infrastructure takedown
The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/deadlock-ransomware-uses-blockchain-to-resist-infrastructure-takedown/)
BleepingComputer
Aug 11, 2026
Sandworm hackers target IT pros with trojanized WireGuard VPN client
Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/sandworm-hackers-target-it-pros-with-trojanized-wireguard-vpn-client/)
The Hacker News
Aug 11, 2026
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks.
The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026.
\"Kimwolf v7 adds an HTTP/2-based
[Read full article on The Hacker News](https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html)
The Hacker News
Aug 11, 2026
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware.
CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44,
[Read full article on The Hacker News](https://thehackernews.com/2026/08/sandworm-linked-uac-0145-uses-fake-job.html)
BleepingComputer
Aug 11, 2026
Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees
Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-on-flight-carrying-def-con-attendees/)
BleepingComputer
Aug 11, 2026
Microsoft releases Windows 10 KB5120249 extended security update
Microsoft has released Windows 10 KB5120249 Extended Security Updates for versions 22H2 and 21H2 to fix security vulnerabilities and bugs. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/windows-10-kb5120249-cumulative-update-released-with-fixes/)
CyberScoop
Aug 11, 2026
Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas
The airline deactivated the network after the crew realized someone was messing with the in-flight system. The feds are investigating.
The post Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/delta-flight-rogue-wifi-investigation-def-con-las-vegas/)
BleepingComputer
Aug 11, 2026
Windows 11 KB5121003 & KB5120240 cumulative updates released
Microsoft has released Windows 11 KB5121003 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5121003-and-kb5120240-cumulative-updates-released/)
The Hacker News
Aug 11, 2026
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience.
\"Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process,\" the Microsoft Threat
[Read full article on The Hacker News](https://thehackernews.com/2026/08/deadlock-ransomware-uses-polygon-smart.html)
BleepingComputer
Aug 11, 2026
Wesco confirms security incident after ExfilSquad claims data theft
Global supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/wesco-confirms-security-incident-after-exfilsquad-claims-data-theft/)
CyberScoop
Aug 11, 2026
NIST wants to overhaul its vulnerability database for the AI age
NIST is seeking public input to modernize the National Vulnerability Database to keep pace with AI-driven cyber threats and machine-scale security data.
The post NIST wants to overhaul its vulnerability database for the AI age appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/nist-national-vulnerability-database-ai-overhaul/)
BleepingComputer
Aug 11, 2026
Mozilla updates GPG signing key for Firefox releases after exposure
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/)
The Hacker News
Aug 11, 2026
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response.
\"Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities and developing exploit chains) and to reduce refusals for certain higher-risk
[Read full article on The Hacker News](https://thehackernews.com/2026/08/openai-launches-gpt-56-cyber-with.html)
BleepingComputer
Aug 11, 2026
DDoS attacks over 1 Tbps surged fivefold in the second quarter
Cloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/ddos-attacks-over-1-tbps-surged-fivefold-in-the-second-quarter/)
The Hacker News
Aug 11, 2026
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over.
Researchers at the University of Birmingham and the security firm Fuzzware tested 26 phones and cellular modules for the capability, found it
[Read full article on The Hacker News](https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html)
The Hacker News
Aug 11, 2026
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories.
That key is how a user, or a Linux distribution packaging the browser, confirms a downloaded Firefox tarball came from Mozilla and was not tampered with.
That decision carries a cost for
[Read full article on The Hacker News](https://thehackernews.com/2026/08/mozilla-revokes-firefox-and-thunderbird.html)
The Hacker News
Aug 11, 2026
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording.
The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver's license and a New York bank account.
The
[Read full article on The Hacker News](https://thehackernews.com/2026/08/researchers-built-fake-crypto-startup.html)
The Hacker News
Aug 11, 2026
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine.
The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that
[Read full article on The Hacker News](https://thehackernews.com/2026/08/researchers-turn-usb-auto-install-into.html)
The Hacker News
Aug 11, 2026
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction.
The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place them in channels the assistant already uses, and let
[Read full article on The Hacker News](https://thehackernews.com/2026/08/malicious-mcp-servers-can-split.html)
BleepingComputer
Aug 11, 2026
US and South Korea warn of Gunra ransomware targeting govt agencies
U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/us-warns-of-gunra-ransomware-attacks-against-government-critical-infrastructure/)
The Hacker News
Aug 11, 2026
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment.
The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still active inside the network, and customers lost neither heat
[Read full article on The Hacker News](https://thehackernews.com/2026/08/hackers-breach-polish-power-plant.html)
The Hacker News
Aug 11, 2026
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads.
\"Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository,\" Wordfence researcher Paolo Tresso said.
[Read full article on The Hacker News](https://thehackernews.com/2026/08/bdthemes-supply-chain-attack-poisons.html)
BleepingComputer
Aug 10, 2026
Hackers breached a small Polish energy plant via private APN last year
Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year/)
CyberScoop
Aug 10, 2026
The FTC wants to regulate AI for ideological bias
The commission is mulling whether to begin regulating bias in AI systems. Critics say they’re overstepping their legal authority and infringing on free speech.
The post The FTC wants to regulate AI for ideological bias appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/ftc-regulating-ai-ideological-bias/)
BleepingComputer
Aug 10, 2026
BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/)
CyberScoop
Aug 10, 2026
OpenAI says Daybreak will expand to offer specialized cyber services
The company rolled out “Red” and “Blue” programs for defenders, introduced a new model and announced partnerships with 16 major cybersecurity vendors.
The post OpenAI says Daybreak will expand to offer specialized cyber services appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/openai-daybreak-expansion-specialized-cyber-services/)
BleepingComputer
Aug 10, 2026
OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users
OpenAI has developed a new model called \"GPT 5.6 Cyber,\" designed for vulnerability research, penetration testing, incident response, and remediation. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/openai-releases-chatgpt-56-cyber-but-its-only-for-approved-users/)
CyberScoop
Aug 10, 2026
U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang
The ransomware-as-a-service outfit has gone after a range of critical infrastructure sectors across the globe.
The post U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/us-south-korea-gunra-ransomware-warning/)
BleepingComputer
Aug 10, 2026
New StormEncryptor ransomware used by former Medusa affiliate
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/new-stormencryptor-ransomware-used-by-former-medusa-affiliate/)
CyberScoop
Aug 10, 2026
UK man tied to The Com sentenced for abusing 117 victims
Justin Swaddle, who was a minor when he committed the crimes, coerced children across multiple countries into self-harm and sexual abuse using threats tied to their personal information, authorities said.
The post UK man tied to The Com sentenced for abusing 117 victims appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/uk-justin-swaddle-the-com-sentenced/)
The Hacker News
Aug 10, 2026
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default.
That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place.
That’s only part of it. Here’s
[Read full article on The Hacker News](https://thehackernews.com/2026/08/weekly-recap-ai-goes-rogue-metabase-0.html)
CyberScoop
Aug 10, 2026
Why transparent AI agents matter more than you think
The difference between a prompt injection attack you'll catch and one you won't might just be whether your AI agent can explain itself.
The post Why transparent AI agents matter more than you think appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/transparent-ai-agent-security-op-ed/)
BleepingComputer
Aug 10, 2026
When Credentials Are No Longer Enough: Device Trust in the AI Era
AI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals such as passwords, MFA, IP reputation, and geolocation become easier to bypass. Specops explains why organizations are increasingly adding device trust to their Zero Trust strategies. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/when-credentials-are-no-longer-enough-device-trust-in-the-ai-era/)
The Hacker News
Aug 10, 2026
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware.
South Korean security firm Genians says it uncovered the
[Read full article on The Hacker News](https://thehackernews.com/2026/08/kimsuky-builds-offline-ai-stack-that.html)
BleepingComputer
Aug 10, 2026
Member of The Com sent to prison for blackmail, sextortion
A member of \"The Com,\" a loose-knit online cybercrime collective that targets children and teenagers, has been sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/member-of-the-com-sent-to-prison-for-blackmail-sextortion/)
The Hacker News
Aug 10, 2026
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on.
Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim's machine, and used a
[Read full article on The Hacker News](https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html)
BleepingComputer
Aug 10, 2026
LexisNexis shuts down services after suspicious activity on servers
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/lexisnexis-shuts-down-services-after-suspicious-activity-on-servers/)
The Hacker News
Aug 10, 2026
Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development
AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed.
When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, losing control of what gets shipped.
[Read full article on The Hacker News](https://thehackernews.com/2026/08/shipping-1050-more-code-watch-this.html)
BleepingComputer
Aug 10, 2026
Valve notifies Steam hardware customers of a data breach
Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/)
The Hacker News
Aug 10, 2026
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro (\"solidity-pro\") that has been observed delivering a browser wallet and credential stealer.
The names of the extensions are below -
helper-beeps.solidity-pro
web3devtoolsx.solidity-pro
Although neither of the extensions is now available on Open VSX, the GitHub repository
[Read full article on The Hacker News](https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html)
The Hacker News
Aug 10, 2026
OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
OpenAI has announced that it's pausing some \"internal activities\" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity.
In response to the discovery, the AI upstart said it's implementing security controls for higher-capability models and associated activities, such as isolated
[Read full article on The Hacker News](https://thehackernews.com/2026/08/openais-next-ai-model-astra-shows-cyber.html)
BleepingComputer
Aug 8, 2026
Hackers breach TrueConf to trojanize client installers with backdoors
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors/)
The Hacker News
Aug 8, 2026
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
New research shows content inside an email can escape its message boundary and interfere with the webmail interface.
Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email.
PortSwigger researcher Gareth
[Read full article on The Hacker News](https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail.html)
BleepingComputer
Aug 7, 2026
Metabase SQLi zero-day exploited in customer data-theft attacks
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/)
BleepingComputer
Aug 7, 2026
Unlimited Technology Systems breach impacts 3.8 million people
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/)
The Hacker News
Aug 7, 2026
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems.
\"These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload,\" OpenSourceMalware researcher Paul
[Read full article on The Hacker News](https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html)
The Hacker News
Aug 7, 2026
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.
The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture.
\"
[Read full article on The Hacker News](https://thehackernews.com/2026/08/clickfix-attacks-deliver-macos-stealer.html)
The Hacker News
Aug 7, 2026
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671.
\"UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their
[Read full article on The Hacker News](https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html)
BleepingComputer
Aug 7, 2026
Levi Strauss & Co. says hackers stole corporate data in cyberattack
Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/levi-strauss-and-co-says-hackers-stole-corporate-data-in-cyberattack/)
CyberScoop
Aug 7, 2026
Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports
The cyberattack hit gate systems at all three North Carolina ports, as officials continue investigating the breach and its effects on operations.
The post Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/north-carolina-ports-cyberattack-coast-guard/)
BleepingComputer
Aug 7, 2026
Real emails, hijacked payments: Two H1 2026 attack chains
Gen's H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/real-emails-hijacked-payments-two-h1-2026-attack-chains/)
BleepingComputer
Aug 7, 2026
North Carolina Ports confirms cyberattack disrupting operations
The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/north-carolina-ports-confirms-cyberattack-disrupting-operations/)
The Hacker News
Aug 7, 2026
Growing Up The Hard Way
Open Source had a great childhood.
For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up — take what you need, pay me back whenever, no need to leave a name. It was idyllic. It was also, in retrospect, a little feral.
Then,
[Read full article on The Hacker News](https://thehackernews.com/2026/08/growing-up-hard-way.html)
The Hacker News
Aug 7, 2026
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Cybersecurity researchers have called attention to an active \"widespread email-driven phishing campaign\" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email.
\"The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,
[Read full article on The Hacker News](https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html)
The Hacker News
Aug 7, 2026
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors.
PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where scanning
[Read full article on The Hacker News](https://thehackernews.com/2026/08/ai-assisted-http-terminator-finds-novel.html)
The Hacker News
Aug 7, 2026
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables.
Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and
[Read full article on The Hacker News](https://thehackernews.com/2026/08/new-natjack-attacks-hijack-tcp-sessions.html)
The Hacker News
Aug 7, 2026
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables.
Presented at Black Hat USA 2026, Stagg said the techniques were demonstrated across network infrastructure devices
[Read full article on The Hacker News](https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html)
The Hacker News
Aug 7, 2026
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain.
\"The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend infrastructure,
[Read full article on The Hacker News](https://thehackernews.com/2026/08/teampcp-linked-to-redis-attacks-dating.html)
BleepingComputer
Aug 6, 2026
OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it
OpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/artificial-intelligence/openai-rolls-out-a-major-chatgpt-upgrade-even-if-you-dont-pay-for-it/)
BleepingComputer
Aug 6, 2026
ClickFix attack pushes macOS infostealer for crypto theft attacks
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/)
PortSwigger Research
Aug 6, 2026
CSS:the bomb inside your inbox
Gareth Heyes - gareth.heyes@portswigger.net - @garethheyes It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this
[Read full article on PortSwigger Research](https://portswigger.net/research/css-the-bomb-inside-your-inbox)
CyberScoop
Aug 6, 2026
Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams
A Senate Foreign Relations Committee hearing explored how 13 federal agencies and myriad foreign governments are wrestling with the problem.
The post Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/senate-hearing-transnational-scam-task-force/)
BleepingComputer
Aug 6, 2026
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/)
CyberScoop
Aug 6, 2026
Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
A scan of internet-connected industrial equipment found 4,400 exposed PLCs, including 22 in cities recently targeted by water system attacks.
The post Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/exposed-rockwell-controllers-water-system-attacks/)
BleepingComputer
Aug 6, 2026
Swiss government SharePoint breach compromised 200 accounts
Switzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/)
CyberScoop
Aug 6, 2026
Ransom Cartel creator sentenced to 16 years in prison
Maksim Silnikau participated in cybercrime since at least 2005. He ran Ransom Cartel from 2021 until his arrest in 2023.
The post Ransom Cartel creator sentenced to 16 years in prison appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/ransom-cartel-creator-sentenced-to-16-years-in-prison/)
BleepingComputer
Aug 6, 2026
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/)
The Hacker News
Aug 6, 2026
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run.
MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the technique INTERRUPT INJECTION. On an AMD Zen 2 machine running Linux 6.14 with every default Spectre v2 mitigation on,
[Read full article on The Hacker News](https://thehackernews.com/2026/08/new-interrupt-injection-attack-can.html)
BleepingComputer
Aug 6, 2026
Meta AI model hacked a company during misconfigured cyber test
Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached Hugging Face. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/meta-ai-model-hacked-a-company-during-misconfigured-cyber-test/)
The Hacker News
Aug 6, 2026
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job.
This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor.
Nothing here is especially mystical.
[Read full article on The Hacker News](https://thehackernews.com/2026/08/threatsday-odysseus-rce-samsung-one.html)
BleepingComputer
Aug 6, 2026
How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore
AI did not create a new browser security problem. It exposed one that enterprises have long been able to ignore. Skyhigh Security explains why browsers have become a critical control point for governing data movement, AI interactions, and modern work. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/how-ai-exposed-a-browser-security-gap-that-enterprises-cannot-ignore/)
The Hacker News
Aug 6, 2026
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network.
Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed
[Read full article on The Hacker News](https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html)
The Hacker News
Aug 6, 2026
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains.
Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet apps used to generate recovery phrases. Coinspect's on-chain analysis puts the measured theft across two sweeps since late May at a lower bound of
[Read full article on The Hacker News](https://thehackernews.com/2026/08/cryptojs-weak-rng-behind-57-million-in.html)
The Hacker News
Aug 6, 2026
Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses
Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address.
Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users' privacy by routing their Safari web traffic through two relays so that no single third-party, including Apple, can determine where the request is originating from
[Read full article on The Hacker News](https://thehackernews.com/2026/08/webkit-proxy-bypasses-can-expose-real.html)
The Hacker News
Aug 6, 2026
AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links.
We observed production websites embedding hidden prompt injection payloads inside \"Ask AI\" buttons on marketing and competitor comparison pages. When a user
[Read full article on The Hacker News](https://thehackernews.com/2026/08/ai-recommendation-poisoning-how-ask-ai.html)
CyberScoop
Aug 6, 2026
The water sector just got it’s wake-up call. Again.
The attack on water systems across seven states was preventable. Utilities had the playbook. They didn't use it.
The post The water sector just got it’s wake-up call. Again. appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/water-utility-cyberattacks-prevention-nozomi-networks-ceo-op-ed/)
The Hacker News
Aug 6, 2026
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Cybersecurity researchers have disclosed details of a \"factory-shipped backdoor\" implanted in at least 20 Chinese router models from Zbtlink.
According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese
[Read full article on The Hacker News](https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html)
The Hacker News
Aug 6, 2026
Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service
A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021.
Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies, including firms in California, New York and Nebraska, and others abroad, according to the Justice Department.
[Read full article on The Hacker News](https://thehackernews.com/2026/08/ransom-cartel-creator-gets-16-years-in.html)
The Hacker News
Aug 6, 2026
Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts.
The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took at least $495,000 from
[Read full article on The Hacker News](https://thehackernews.com/2026/08/snowflake-hacker-pleads-guilty-over.html)
PortSwigger Research
Aug 5, 2026
CRLF-Powered Desync Attacks: Beheading HTTP Streams
Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power
[Read full article on PortSwigger Research](https://portswigger.net/research/crlf-powered-desync-attacks)
BleepingComputer
Aug 5, 2026
Ransom Cartel ransomware creator sentenced to 16 years in prison
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison/)
BleepingComputer
Aug 5, 2026
Canadian pleads guilty to Snowflake cloud data-theft attacks
A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks/)
CyberScoop
Aug 5, 2026
Snowflake hacker pleads guilty, faces up to 32 years in prison
Connor Moucka obtained almost $500,000 for playing a key role in one of the most widespread and damaging cyberattack sprees on record.
The post Snowflake hacker pleads guilty, faces up to 32 years in prison appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/connor-moucka-guilty-snowflake-attack-spree/)
BleepingComputer
Aug 5, 2026
Hackers run khunt post-exploitation toolkit from Oracle database
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-run-khunt-post-exploitation-toolkit-from-oracle-database/)
PortSwigger Research
Aug 5, 2026
Can AI do novel security research? Meet the HTTP Terminator
Abstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Buildi
[Read full article on PortSwigger Research](https://portswigger.net/research/http-terminator)
The Hacker News
Aug 5, 2026
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.
The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download. Microsoft
[Read full article on The Hacker News](https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html)
BleepingComputer
Aug 5, 2026
COLDCARD security audit phishing attack installs remote access tool
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/coldcard-security-audit-phishing-attack-installs-remote-access-tool/)
The Hacker News
Aug 5, 2026
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms.
One such service, Poison Claude, claims to offer access to Anthropic's large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6.
\"Advertisements for Poison Claude
[Read full article on The Hacker News](https://thehackernews.com/2026/08/poison-claude-sells-discounted-claude.html)
BleepingComputer
Aug 5, 2026
Google Blogger locks hundreds of blogs in malware false positive
Google has locked hundreds of Blogger websites after a false positive claimed they violated its \"Malware and Similar Malicious Content\" policy, with some sites deleted from the platform. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/google/google-blogger-locks-hundreds-of-blogs-in-malware-false-positive/)
BleepingComputer
Aug 5, 2026
How AI-powered phishing killed blocklists for good
AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection offers a more durable defense than relying on domains, signatures, and other known-bad indicators. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/how-ai-powered-phishing-killed-blocklists-for-good/)
The Hacker News
Aug 5, 2026
Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.
The new dead drop resolver approach, observed in two trojanized npm package \"bianira-ui\" and \"fluid-type-ui,\" has been codenamed NullReceiver by
[Read full article on The Hacker News](https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html)
The Hacker News
Aug 5, 2026
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.
The new dead drop resolver approach, observed in two trojanized npm packages \"bianira-ui\" and \"fluid-type-ui,\" has been codenamed NullReceiver by
[Read full article on The Hacker News](https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html)
CyberScoop
Aug 5, 2026
Open-source software’s archenemy TeamPCP goes back further than anyone thought
Oligo Security uncovered evidence of a long operational history, including multiple previous attacks it traced to the same attacker infrastructure and tools.
The post Open-source software’s archenemy TeamPCP goes back further than anyone thought appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/teampcp-long-active-history-2020-oligo-security/)
The Hacker News
Aug 5, 2026
Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data.
The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud,
[Read full article on The Hacker News](https://thehackernews.com/2026/08/kali365-weaponizes-microsoft.html)
The Hacker News
Aug 5, 2026
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability.
We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896
[Read full article on The Hacker News](https://thehackernews.com/2026/08/leaked-n8n-api-tokens-exposed-live.html)
The Hacker News
Aug 5, 2026
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed.
The \"evil twin\" extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been removed from Open VSX as of
[Read full article on The Hacker News](https://thehackernews.com/2026/08/open-vsx-removes-77-malicious-evil-twin.html)
CyberScoop
Aug 5, 2026
AI is getting better at election facts, but voters shouldn’t rely on it
AI chatbots are avoiding some of the obvious errors that plagued earlier models, but they still fall short giving voters the full picture compared to state and local sources.
The post AI is getting better at election facts, but voters shouldn’t rely on it appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/ai-chatbots-2026-midterm-elections/)
The Hacker News
Aug 5, 2026
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK's AI Security Institute.
When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch history to erase the evidence, and posted from a second account it controlled to vouch for
[Read full article on The Hacker News](https://thehackernews.com/2026/08/claude-mythos-5-tried-to-backdoor-real.html)
The Hacker News
Aug 5, 2026
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Cybersecurity researchers have disclosed what has been described as a \"long-standing supply chain attack\" on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users.
According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to deliver FDMTP, a
[Read full article on The Hacker News](https://thehackernews.com/2026/08/quickfox-supply-chain-attack-delivers.html)
CyberScoop
Aug 5, 2026
National cyber director lays out White House plans to secure AI without writing new rules
The Trump administration executive order on artificial intelligence tried to strike the balance between responsible use, security and mutual benefit, all with an eye toward not making it regulatory in nature, National Cyber Director Sean Cairncross said Tuesday. “Everyone is working towards the same goal in terms of protecting the country and securing our systems, […]
The post National cyber director lays out White House plans to secure AI without writing new rules appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/trump-ai-executive-order-open-source-strategy-sean-cairncross/)
BleepingComputer
Aug 4, 2026
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people outside the intended testing boundaries. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/openai-anthropic-ai-agents-targeted-real-people-and-systems-in-cyber-tests/)
CyberScoop
Aug 4, 2026
AISI, OpenAI report more ‘unsanctioned’ model hacks
Following similar reports by OpenAI and Anthropic, the UK’s top AI testing lab and a private cybersecurity tester say their models exploited parts of the open internet.
The post AISI, OpenAI report more ‘unsanctioned’ model hacks appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/aisi-openai-report-unsanctioned-ai-model-hacks/)
CyberScoop
Aug 4, 2026
Massive supply-chain attack compromises 440 packages under four hours
Researchers from multiple security firms observed a variant of Mini Shai-Hulud, self-replicating malware linked to TeamPCP, in all the affected packages.
The post Massive supply-chain attack compromises 440 packages under four hours appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/supply-chain-attack-malware-mini-shai-hulud-teampcp/)
BleepingComputer
Aug 4, 2026
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/)
BleepingComputer
Aug 4, 2026
New XCSSET variant targets macOS devs via compromised Xcode projects
A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/new-xcsset-variant-targets-macos-devs-via-compromised-xcode-projects/)
BleepingComputer
Aug 4, 2026
77 Open VSX extensions found harvesting developer info
77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/)
CyberScoop
Aug 4, 2026
Dem senators criticize Trump administration decisionmaking on AI security risks
The five senators said the administration has alternated between being too passive and overstepping, and China stands to benefit as a result.
The post Dem senators criticize Trump administration decisionmaking on AI security risks appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/trump-ai-policy-chinese-models-risk/)
The Hacker News
Aug 4, 2026
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.
\"Greatness supports AiTM [adversary-in-the-middle] credential and
[Read full article on The Hacker News](https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html)
BleepingComputer
Aug 4, 2026
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/)
CyberScoop
Aug 4, 2026
Prolific ransomware group behind SonicWall zero-day attacks
INC ransomware wasn’t the first group to exploit the zero-days, but it’s been the most assertive and effective in chaining both vulnerabilities to steal and encrypt data for extortion.
The post Prolific ransomware group behind SonicWall zero-day attacks appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/inc-ransomware-sonicwall-zero-day-attacks/)
BleepingComputer
Aug 4, 2026
Varonis Agent IBAC keeps AI agents within their intended boundaries
AI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user's intent. Varonis explains how Agent IBAC detects intent drift and enforces real-time guardrails to keep agents within their intended boundaries. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/varonis-agent-ibac-keeps-ai-agents-within-their-intended-boundaries/)
The Hacker News
Aug 4, 2026
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026.
SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later reported at least 868 packages
[Read full article on The Hacker News](https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html)
The Hacker News
Aug 4, 2026
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect.
The campaign has been codenamed SMOKE#SCREEN by Securonix Threat
[Read full article on The Hacker News](https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html)
The Hacker News
Aug 4, 2026
When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted
The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise.
That assumption is starting to break.
Security teams have long estimated risk by ranking attacker sophistication. Nation-state actors sat at one end. Organized criminal groups followed. Inexperienced attackers, dismissed as \"script kiddies,\" sat at the other end, running public
[Read full article on The Hacker News](https://thehackernews.com/2026/08/when-vibe-hacking-turns-ai-into-junior.html)
The Hacker News
Aug 4, 2026
Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent.
The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so that comment satisfied
[Read full article on The Hacker News](https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html)
The Hacker News
Aug 4, 2026
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.
\"The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second
[Read full article on The Hacker News](https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html)
BleepingComputer
Aug 4, 2026
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/)
BleepingComputer
Aug 3, 2026
New Pass-ta-key attacks let malware hijack Google-synced passkeys
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/)
BleepingComputer
Aug 3, 2026
New DOUBLECUP ClickFix service hides malware in browser cache images
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/)
BleepingComputer
Aug 3, 2026
Fake Roblox Xeno script launcher pushes infostealer, RAT malware
Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/fake-roblox-xeno-script-launcher-pushes-infostealer-rat-malware/)
The Hacker News
Aug 3, 2026
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments.
One of the packages in question is \"lib-mtop,\" an unscoped package with the same name as a private Alibaba package
[Read full article on The Hacker News](https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html)
The Hacker News
Aug 3, 2026
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen.
Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master key
[Read full article on The Hacker News](https://thehackernews.com/2026/08/google-password-manager-attacks-could.html)
BleepingComputer
Aug 3, 2026
ExfilSquad hackers leak info of over 100,000 UK police officers, staff
A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/exfilsquad-hackers-leak-info-of-over-100-000-uk-police-officers-staff/)
BleepingComputer
Aug 3, 2026
Inside the Underground Business of BTMOB RAT
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/)
BleepingComputer
Aug 3, 2026
Inside the Underground Business of the Android BTMOB RAT malware
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/)
The Hacker News
Aug 3, 2026
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended.
Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from
[Read full article on The Hacker News](https://thehackernews.com/2026/08/weekly-recap-rogue-ai-models-88m.html)
The Hacker News
Aug 3, 2026
FOMO in the SOC: Where AI Platforms like Claude Actually Fit
AI is moving incredibly fast, and every security leader is feeling the pressure to keep up.
AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. The conversation has evolved from whether AI belongs in the SOC, to where each type of AI delivers the most value.
With so many new AI
[Read full article on The Hacker News](https://thehackernews.com/2026/08/fomo-in-soc-where-ai-platforms-like.html)
The Hacker News
Aug 3, 2026
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit.
Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain that also hosts the exploit toolkit.
\"
[Read full article on The Hacker News](https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html)
The Hacker News
Aug 3, 2026
PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web.
The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers.
The incident, identified on July 26, also exposed some names
[Read full article on The Hacker News](https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html)
CyberScoop
Aug 3, 2026
CrowdStrike: AI is now both the weapon and the target in cyberattacks
AI generates 2.5 signals for every human-triggered signal CrowdStrike has to assess. Meanwhile, attackers are using AI to weaponize vulnerabilities faster than companies can patch them.
The post CrowdStrike: AI is now both the weapon and the target in cyberattacks appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/crowdstrike-annual-threat-hunting-report-2026/)
The Hacker News
Aug 3, 2026
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.
Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version.
N-central is the remote monitoring and management platform
[Read full article on The Hacker News](https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html)
BleepingComputer
Aug 2, 2026
OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems
OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/artificial-intelligence/openai-teases-astra-its-next-major-ai-model-after-it-solves-10-long-standing-math-problems/)
BleepingComputer
Aug 2, 2026
Google Chrome may soon block New Tab hijacker extensions by default
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/google/google-chrome-may-soon-block-new-tab-hijacker-extensions-by-default/)
The Hacker News
Aug 1, 2026
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses.
Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities.
Anyone who visited a site carrying the affected script on July 27 and copied a Bitcoin,
[Read full article on The Hacker News](https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html)
The Hacker News
Aug 1, 2026
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report.
Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard, also known as
[Read full article on The Hacker News](https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html)
BleepingComputer
Jul 31, 2026
Amgen says cloud data breach exposed patient health, proprietary info
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/amgen-says-cloud-data-breach-exposed-patient-health-proprietary-info/)
BleepingComputer
Jul 31, 2026
Arch Linux disables AUR package adoption to stop malware flood
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/arch-linux-disables-aur-package-adoption-to-stop-malware-flood/)
BleepingComputer
Jul 31, 2026
Online ad firm Adform’s script compromised to steal cryptocurrency
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/)
CyberScoop
Jul 31, 2026
Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world
The president went against his intelligence agencies’ conclusions about Iran being the likely suspect in the campaign.
The post Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/trump-blames-minnesota-water-cyberattacks-iran/)
The Hacker News
Jul 31, 2026
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025.
These targeted organizations operate across several sectors, such as healthcare, research, government offices,
[Read full article on The Hacker News](https://thehackernews.com/2026/08/suspected-chinese-speaking-hackers.html)
BleepingComputer
Jul 31, 2026
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers/)
BleepingComputer
Jul 31, 2026
CISA warns of cyberattacks disrupting U.S. water utilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/cisa-warns-of-cyberattacks-disrupting-us-water-utilities/)
The Hacker News
Jul 31, 2026
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators.
Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019.
The same apps have a second job. When a box
[Read full article on The Hacker News](https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html)
The Hacker News
Jul 31, 2026
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months.
Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range of apps and use-cases that it wasn't originally
[Read full article on The Hacker News](https://thehackernews.com/2026/07/6-reasons-why-device-code-phishing-is.html)
CyberScoop
Jul 31, 2026
What the Hugging Face breach reveals about defense in the age of agentic AI
We almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models, including GPT-5.6 Sol along with an unreleased […]
The post What the Hugging Face breach reveals about defense in the age of agentic AI appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/hugging-face-breach-agentic-ai-security-op-ed/)
CyberScoop
Jul 31, 2026
Anthropic says its AI accidentally hacked three companies during safety tests
Following OpenAI’s own incident, Anthropic reviewed its own evaluations and found three cases of Claude hacking external companies.
The post Anthropic says its AI accidentally hacked three companies during safety tests appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/anthropic-claude-ai-hacks-real-companies/)
BleepingComputer
Jul 31, 2026
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/anthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests/)
CyberScoop
Jul 30, 2026
Okta’s deal for Permiso aims to close gaps in identity threat detection
Ely Kahn, Okta's chief product officer, told CyberScoop the deal enriches the company's current threat detection tools and gives it deeper visibility into AI agent activity across enterprise systems.
The post Okta’s deal for Permiso aims to close gaps in identity threat detection appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/okta-acquires-permiso-security-ai-identity-threat-detection/)
CyberScoop
Jul 30, 2026
CISA issues recommendations to federal agencies on open-source software security
One expert said they were pleased by the guidance, which touches on open-weight AI models, patching and more.
The post CISA issues recommendations to federal agencies on open-source software security appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/cisa-open-source-software-security-guidance/)
PortSwigger Research
Feb 5, 2026
Top 10 web hacking techniques of 2025
Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year
[Read full article on PortSwigger Research](https://portswigger.net/research/top-10-web-hacking-techniques-of-2025)
PortSwigger Research
Jan 6, 2026
Top 10 web hacking techniques of 2025: call for nominations
Update: nominations are now closed, and voting is live! Cast your vote here Over the last year, security researchers have shared a huge amount of work with the community through blog posts, presentati
[Read full article on PortSwigger Research](https://portswigger.net/research/top-10-web-hacking-techniques-of-2025-nominations-open)
PortSwigger Research
Dec 10, 2025
The Fragile Lock: Novel Bypasses For SAML Authentication
TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusi
[Read full article on PortSwigger Research](https://portswigger.net/research/the-fragile-lock)
PortSwigger Research
Nov 11, 2025
Introducing HTTP Anomaly Rank
HTTP Anomaly Rank If you've ever used Burp Intruder or Turbo Intruder, you'll be familiar with the ritual of manually digging through thousands of responses by repeatedly sorting the table via length,
[Read full article on PortSwigger Research](https://portswigger.net/research/introducing-http-anomaly-rank)
PortSwigger Research
Sep 17, 2025
WebSocket Turbo Intruder: Unearthing the WebSocket Goldmine
Many testers and tools give up the moment a protocol upgrade to WebSocket occurs, or only perform shallow analysis. This is a huge blind spot, leaving many bugs like Broken Access Controls, Race condi
[Read full article on PortSwigger Research](https://portswigger.net/research/websocket-turbo-intruder-unearthing-the-websocket-goldmine)