Loading…

Whats The Hax?

Daily intelligence on threats, breaches, and defenders

Latest
BleepingComputerNew HollowGraph malware uses Microsoft Graph for stealthy C2 commsLatest newsI tested a 4TB quantum-resistant USB drive - but you don't have to spend $3000 for this securityThe Hacker NewsExposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware CampaignHelp Net SecurityHOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channelThe Record from Recorded Future NewsMore than 1,000 domains illegally streaming World Cup games seized, DOJ saysLatest newsThe best rugged phones in 2026: Expert testedLatest newsAn AI agent breached Hugging Face before an AI defender caught it: What users should do nextLatest newsWhy I still recommend Synology's DS225+ NAS - even if it can't replace your cloud storageCisco Security AdvisoryCisco Identity Services Engine Stored Cross-Site Scripting VulnerabilitiesThe Record from Recorded Future NewsHackers were inside South Korea's diplomat training system for 9 monthsSecurityWeekNeo Emerges From Stealth With $100M to Control and Secure Enterprise AI SoftwareHelp Net SecurityPaidwork breach exposes sensitive data of 23 million userThe Record from Recorded Future NewsRomania races to restore land registry after cyberattack disrupts property marketThe Hacker NewsHollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050Help Net SecurityServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)Latest newsHow I configure DNS on Ubuntu Linux distros via the command line - it's easier than you thinkSecurityWeekSonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before PatchJohn HammondRedirect Chain AbuseBleepingComputerAn AI SOC Evaluation Guide for Security LeadersSecurity - Ars TechnicaPay up or not? Ransomware surge has victims facing tough choices.BleepingComputerNew HollowGraph malware uses Microsoft Graph for stealthy C2 commsLatest newsI tested a 4TB quantum-resistant USB drive - but you don't have to spend $3000 for this securityThe Hacker NewsExposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware CampaignHelp Net SecurityHOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channelThe Record from Recorded Future NewsMore than 1,000 domains illegally streaming World Cup games seized, DOJ saysLatest newsThe best rugged phones in 2026: Expert testedLatest newsAn AI agent breached Hugging Face before an AI defender caught it: What users should do nextLatest newsWhy I still recommend Synology's DS225+ NAS - even if it can't replace your cloud storageCisco Security AdvisoryCisco Identity Services Engine Stored Cross-Site Scripting VulnerabilitiesThe Record from Recorded Future NewsHackers were inside South Korea's diplomat training system for 9 monthsSecurityWeekNeo Emerges From Stealth With $100M to Control and Secure Enterprise AI SoftwareHelp Net SecurityPaidwork breach exposes sensitive data of 23 million userThe Record from Recorded Future NewsRomania races to restore land registry after cyberattack disrupts property marketThe Hacker NewsHollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050Help Net SecurityServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)Latest newsHow I configure DNS on Ubuntu Linux distros via the command line - it's easier than you thinkSecurityWeekSonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before PatchJohn HammondRedirect Chain AbuseBleepingComputerAn AI SOC Evaluation Guide for Security LeadersSecurity - Ars TechnicaPay up or not? Ransomware surge has victims facing tough choices.

By Source

Feeds organized so you can skim by site.

Density Sort
BL
BleepingComputer
1h ago · 15 items
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms 1h ago A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. An AI SOC Evaluation Guide for Security Leaders 4h ago Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy,... Hugging Face warns an autonomous AI agent hacked its network 6h ago The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. Microsoft confirms Windows Server Update Services sync delays 7h ago Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. Windows KB5121767 OOB update fixes shutdowns on some Dell PCs 8h ago Microsoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates. Critical ServiceNow code execution flaw now exploited in attacks 8h ago Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. Hackers abuse ViPNet software to target Russian govt agencies 1d ago An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. Update now: 7-Zip fixes RCE flaw exploitable with malicious archives 1d ago 7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. WordPress Core "wp2shell" RCE flaws get public exploits, patch now 2d ago Public exploits have been released for the critical Microsoft warns of surge in ACR Stealer attacks on customers 2d ago Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers.
15 loaded
LN
Latest news
1h ago · 20 items
I tested a 4TB quantum-resistant USB drive - but you don't have to spend $3000 for this security 1h ago Apricorn's new 4TB Aegis Secure Key is the biggest-capacity hardware-encrypted flash drive on the market right now. The best rugged phones in 2026: Expert tested 1h ago Most mainstream phones are durable enough for everyday use, but if you're the adventure-seeking kind, check out our top rugged phones. An AI agent breached Hugging Face before an AI defender caught it: What users should do next 1h ago An agentic AI infiltrated the production infrastructure of an AI project. Then an AI detected it. Is this the future of cyberattacks, and how will they be defended against? Why I still recommend Synology's DS225+ NAS - even if it can't replace your cloud storage 1h ago Soaring hard drive prices are making NAS boxes a niche product, but the Synology DS225+ still makes sense. Here's why. How I configure DNS on Ubuntu Linux distros via the command line - it's easier than you think 3h ago DNS is a critical component for PC networking, searching, and security. If you want to learn how to set it up on Ubuntu-based distros from the command line, here's how. How to check if ChatGPT and other AI tools cite your website - and improve your chances in 2026 4h ago SEO is not dead. Here's how to get cited more often and boost search visibility in AI tools today. I tested 3 blood pressure trackers for a month - only one rivaled my Garmin Index BP Monitor 5h ago I tested Samsung, Amazfit, and Doctor Fit blood pressure watches - and only one rivaled my Garmin Index BP Monitor. The top AI fear for 6,000 tech pros isn't losing their jobs - it's more work for the same pay 5h ago Most tech professionals wouldn't recommend their own role to someone entering the industry today. I recreated OpenAI's Codex Micro for a lot less - and mine is more customizable 5h ago The $230 Codex Micro sold out before I could buy one, so I turned my Stream Deck+ into a surprisingly capable alternative. Sign up for T-Mobile Fiber 2 Gig and get $100 back, plus a month included 8h ago T-Mobile Fiber's latest offer covers your first month and pays you $100 back on the 2 Gig plan. Here's all you need to know.
20 loaded
TH
The Hacker News
1h ago · 20 items
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign 1h ago HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 3h ago ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More 4h ago Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine 5h ago Mythos Didn't Break Your Security Program. Your Exposure Window Could. 6h ago New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction 8h ago Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs 9h ago World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent 12h ago SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines 12h ago Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution 21h ago
20 loaded
HN
Help Net Security
1h ago · 10 items
HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel 1h ago HOLLOWGRAPH malware hides stolen files and commands inside a Microsoft 365 calendar, using events dated to the year 2050 to dodge detection. Paidwork breach exposes sensitive data of 23 million user 3h ago A data breach at Paidwork, a microtask platform, has exposed personal and financial information belonging to more than 23 million users. ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) 3h ago Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform. Italy fines WINDTRE €1.7 million over security flaws behind two data breaches 4h ago Italy's privacy regulator issued a €1.7 million fine against WINDTRE after social engineering attacks exposed data for 365,000 customers. Hugging Face breached by autonomous AI agent 7h ago Hugging Face has been breached by an autonomous AI agent system via code-execution paths in the dataset processing pipeline. The Windows 10 hangover is becoming a security problem 9h ago Millions of Windows 10 devices remain in use after end of support, exposing organizations to growing security and compliance risks. Meet Dusseldorf, Microsoft’s open-source out-of-band security platform 12h ago The Microsoft Dusseldorf OAST platform captures DNS and HTTP callbacks to detect out-of-band flaws like SSRF and XSS in your own private lab. More alerts are making your team slower, and an outcome-based SOC fixes that 12h ago More alerts slow you down. See how an outcome based SOC uses detection engineering, AI tuning, and MDR to cut dwell time and stop attackers. A forensic tool for backdoored code completions in AI assistants 13h ago A new forensic tool traces backdoored code completions from AI coding assistants back to the poisoned training data that caused them. Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security 13h ago ZoneAlarm Mobile Security is a security app from Check Point designed to protect mobile devices against phishing, malicious websites, unsafe networks, and
CS
Cisco Security Advisory
2h ago · 20 items
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities 2h ago Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulner... Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability 4d ago A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local ... Cisco Advance Notification for Publication of July 15, 2026, Security Advisories 5d ago On July 15, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: Identity Services Engine... Cisco RoomOS Security Hardening Release: July 2026 5d ago As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses m... Cisco Identity Services Engine Path Traversal Vulnerability 5d ago A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or ... Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities 13d ago Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to achieve remote code execution or conduct information disclosure attacks on an affected devi... Cisco Catalyst Center Arbitrary File Read Vulnerability 14d ago A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exp... ClamAV Vulnerabilities Affecting Cisco Products: July 2026 17d ago Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For... Cisco Advance Notification for Publication of July 1, 2026, Security Advisories 19d ago On July 1, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: Catalyst Center Secure En... Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability 19d ago A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery...
20 loaded
SE
SecurityWeek
3h ago · 10 items
JH
John Hammond
4h ago · 15 items
15 loaded
SA
Security - Ars Technica
4h ago · 20 items
Pay up or not? Ransomware surge has victims facing tough choices. 4h ago Now, even Russia's most elite hackers are using Clickfix to infect devices 3d ago Windows 0-day drops the same day Microsoft releases record number of patches 4d ago Microsoft’s Secure Boot has been broken for a decade and no one noticed until now 5d ago The US government warns that Russia state hackers are coming after your router 6d ago Now, defenders are embracing the prompt injection, too 7d ago Patch for Windows Defender 0-day could allow attackers to fill hard disk 10d ago Google pays $250K for Linux vulnerability allowing guest VM escapes 11d ago Hackers can use 9 of the most popular AI tools to assemble massive botnets 12d ago Newly discovered PamStealer isn't your typical macOS malware 17d ago
20 loaded
MS
MSRC Security Update Guide
4h ago · 20 items
CVE-2026-50650 .NET Framework Elevation of Privilege Vulnerability 4h ago CVE-2024-35248 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability 4h ago CVE-2026-62389 ws < 8.21.1 Default maxFragments Allows Memory Exhaustion DoS 9h ago CVE-2026-45784 rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers 9h ago CVE-2026-63808 exfat: fix potential use-after-free in exfat_find_dir_entry() 10h ago CVE-2026-53381 virtiofs: fix UAF on submount umount 10h ago CVE-2026-63827 apparmor: fix use-after-free in rawdata dedup loop 10h ago CVE-2026-53398 NFSD: Fix SECINFO_NO_NAME decode error cleanup 10h ago CVE-2026-63795 9p: avoid putting oldfid in p9_client_walk() error path 10h ago CVE-2026-53382 media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si 10h ago
20 loaded
DA
darkreading
4h ago · 20 items
20 loaded
CD
Cyber Defense Magazine
4h ago · 10 items
SL
Security Latest
8h ago · 20 items
The ACLU Is Arming Lawyers to Expose State Surveillance Secrets 8h ago Apps Marketed to US Troops Are Shipping Chinese and Russian Code 8h ago Your Period Tracker Is (Probably) Spying on You 2d ago Prompt Injection Attacks Are Thwarting AI Hacking Agents 2d ago San Francisco Demands Apple and Google Delete AI ‘Nudify’ Apps From App Stores 3d ago Here’s the Truth About Whether Meta’s NameTag Face Recognition Tech ‘Exists’ 4d ago A Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban Surveillance 7d ago AI Found a Root Bug in Linux That Everyone Missed for 15 Years 9d ago A Majority of European Lawmakers Voted Against Letting Big Tech Read Our Messages. They’re Going to Anyway 11d ago Madison Square Garden Kept a List of Gay Celebrities 11d ago
20 loaded
RF
Recorded Future
18h ago · 20 items
Threat Hunting: A Guide | Recorded Future 18h ago Tracking Advanced Persistent Threat Groups | Recorded Future 3d ago AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict 4d ago The Shift: A New Era of AI Regulation 5d ago The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Future 6d ago June 2026 CVE Landscape 10d ago RiskX interview video featuring Colin Mahony and Mastercard's Aditi Sawhney 11d ago The Threat Isn’t the Frontier Model 12d ago Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool 19d ago Where Expertise Meets Algorithm: The Insikt Group® Intelligence Edge 25d ago Discover how Recorded Future’s Insikt Group combines human expertise with automated analysis to turn raw data into actionable, industry-leading threat intelligence.
20 loaded
NE
NetworkChuck
1d ago · 15 items
15 loaded
IP
IppSec
2d ago · 15 items
15 loaded
MS
Microsoft Security Blog
3d ago · 10 items
Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks 3d ago Join Microsoft Security at Black Hat USA 2026 for supply chain research, hands-on security experiences, expert conversations, and our reception. ACR Stealer: Two observed intrusion chains amid increased threat activity 3d ago From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication token... Least privilege for AI agents: Identity, access, and tool binding 4d ago As AI agents become more autonomous, strong identity, access, and auditing controls are critical to keeping them secure. Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery 4d ago Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defenses. Turning threat intelligence into decisive action with Defender Experts 5d ago Security teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a sprawling mix of third-party tools. Defending SaaS-based applications against ShinyHunters OAuth abuse 6d ago Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS-bas... Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID 7d ago Starting September 1, 2026, passkeys will become the default authentication experience in Microsoft Entra. Read more about how to prepare. Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative 10d ago Microsoft’s latest Secure Future Initiative report outlines progress on secure foundations, AI-powered defense, and future-ready cybersecurity. GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware 11d ago GigaWiper is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational platform. This blog analyzes how the malware incorporates code from several previously separate malware families an... Protecting Microsoft at AI speed: How SFI proactively hardens our cloud 12d ago Learn how Microsoft uses AI to proactively harden its own cloud services through the Secure Future Initiative (SFI).
HS
Heimdal Security Blog
3d ago · 15 items
MediaArena malvertising: why a quarantine isn’t the end of the incident 3d ago If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win. Our SOC data says treat it as a live persistence incident instead. In the case we timed, the payload finished writing i... Top 6 Managed Detection and Response Providers 10d ago There are several major managed detection and response (MDR) companies to choose from. We’ve compared the main offerings of the best MDR providers to help you decide which is right for your organisation. Maybe it was a near miss, or a secur... Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors 12d ago Your client is no longer just buying your security advice. They’re auditing whether you live by it. That was a clear message from my exclusive interview with Heather MacDonald Alford, an MSP finance specialist and owner of Counting Creators... How to scale your patches without scaling your team (the patch wave) 17d ago Most breaches don’t start with a vulnerability nobody knew about. They start with one nobody patched in time. Vulnerability exploitation is now the single biggest way attackers get into a network. It has overtaken stolen credentials for the... AI didn’t break patching. It showed us patching was already broken. 17d ago Claude Mythos, an AI model from Anthropic, has found 23,019 software vulnerabilities in the past month. Fewer than 1% of them have been patched. That gap is the story. Finding a vulnerability used to be the hard part, the thing that limited... Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes 19d ago New feature reduces manual setup, speeds up customer activation, and helps MSPs scale Microsoft CSP estates with less operational work. How Dynamic Defense shuts an attacker out without shutting down the business 24d ago AI has handed hackers a resource advantage. Winning it back means spending your own resources far more precisely, and that’s the strategy we call Dynamic Defense. The principle is simple. Contain the threat just enough, for just long enough... Static security has run out of road. The case for Dynamic Defense 24d ago AI has flipped the economics of cybersecurity in the attacker’s favor. For most of the last decade, defenders held the cost advantage, buying down their risk with a stack of largely static controls. That advantage is gone, and winning it ba... Breaking the MSP Echo Chamber: The Power of Community 26d ago MSPs spend too much time talking to other MSPs and not enough time talking to the people they’re supposed to serve. That’s Paul Croker’s view of some of the channel’s biggest growth problems. While most industry events bring technology prof... How attackers built a RAT on a Windows machine using its own .NET compiler 28d ago In May 2026 an attacker compromised a UK medical practice endpoint without delivering a single malicious file. They used PowerShell and the .NET compiler built into Windows to build a Remcos remote access trojan on the machine itself, so si...
15 loaded
No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE 4d ago [$13337] Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking 4d ago ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping via Unvalidated IOCTL 4d ago HN Security - My Semgrep C/C++ ruleset is ready for prime time again 5d ago The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets 5d ago (More) Unauthenticated Arbitrary Code Execution in ServiceNow 5d ago Smashing the ServiceNow Sandbox – Pre Authentication RCE 6d ago Context Bombs: Using AI Guardrails as a defensive mechanism 6d ago CET-Compliant Callstack Spoofing via Thread Pool & Enum Callback Trampolining (Rust PoC) 6d ago Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) 7d ago
293 loaded
SE
Securelist
4d ago · 10 items
HelloNet campaign — new malicious modules launched through the ViPNet update system 4d ago We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks). GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration 4d ago Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia. OkoBot: new sophisticated malware framework targets cryptocurrency users 5d ago Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the R... Threat landscape for industrial automation systems. Q1 2026 13d ago This report contains industrial threat statistics for Q1 2026, including industrial threat distribution by type, source, region and industry. When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website 14d ago The OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers. Today, threat actors are weaponizing it. Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign 17d ago An inside look at the active Armored Likho APT campaign. The attackers are using spear-phishing, AI-generated loaders, and a new Python-based tool, BusySnake Stealer, to target organizations in Russia, Kazakhstan, and Brazil. Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects 18d ago Kaspersky Compromise Assessment specialists analyze trends from the service’s 2025 projects and provide tips on how to enhance your organization’s security. The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign 19d ago Kaspersky experts have uncovered a malicious network infrastructure for delivering AsyncRAT. The Trojan is dropped via compromised ScreenConnect software. In this post, we break down the infection chain and analyze the C2 infrastructure. OpenClaw: risks for the users and how to mitigate them 19d ago Researching OpenClaw vulnerabilities, malicious skills and other security issues with the popular agent, and providing tips on how to mitigate them. ToddyCat: your hidden email assistant. Part 2 20d ago An in-depth analysis of Umbrij, a new tool used by the ToddyCat APT group to compromise corporate email communications in Gmail. The attack targeted OAuth authorization tokens, allowing threat actors to gain access to Google services.
BH
Black Hat
5d ago · 15 items
15 loaded
HA
Hak5
5d ago · 15 items
15 loaded
TL
The Last Watchdog
5d ago · 34 items
News alert: Pulse Security launches with $8 million for AI platform to modernize CISO operations 5d ago SAN FRANCISCO, July 15, 2026, CyberNewswire – Backed by Foundation Capital and Zetta Venture Partners with $8M in seed funding, Pulse Security delivers the program intelligence and agentic infrastructure that security leaders have been mi... News alert: Insignary’s on-demand SBOM verification boosts software supply chain security 5d ago TORONTO, July 15, 2026, CyberNewswire ŌĆō According to Insignary Inc., a leader in software supply chain security and binary software composition analysis (SCA), most organizations cannot independently verify what is actually inside the sof... News alert: Tego AI finds Anthropic’s integration of Claude and Slack can trigger unauthorized actions 5d ago TEL AVIV, Israel, July 14, 2026, CyberNewswire – Tego AI, a cybersecurity company, published new research identifying a potentially critical security weakness in Claude Tag, Anthropic’s native integration between Claude and Slack. Resea... News alert: OpenMatter joins HOL initiative to shape trust standards for autonomous AI 12d ago MELBOURNE, Fla., July 8, 2026, CyberNewswire – OpenMatter Network today announced that it has joined the founding group of organizations participating in the Hashgraph Online (HOL) Partner Program, where the company will help develop stan... News alert: Insignary tackles SBOM accuracy gap as AI tools intensify software supply-chain risk 14d ago TORONTO, July 6, 2026, CyberNewswire тАУ Insignary, Inc., whose patented binary fingerprint technology has been cited in four Gartner research reports, today announced its recognition as a Sample Vendor for Reachability Analysis in the Gart... News alert: Link11 launches faster DDoS mitigation to counter AI-driven, adaptive network attacks 18d ago FRANKFURT, July 1, 2026, CyberNewswire – Link11, a leading European provider of cloud-based cybersecurity solutions, today announced the launch of its completely rebuilt Layer 3/4 DDoS mitigation solution, designed to address the growing ... News alert: Reflectiz partners with Taboola to host webinar on AI-driven marketing security risks 19d ago BOSTON, June 30, 2026, CyberNewswire – Reflectiz, the web exposure management platform, today announced a live webinar with Taboola, "Securing Third-Party Marketing in the AI Era," taking place July 8 at 9 AM EDT / 3 PM CEST. Every market... News alert: OpenMatter launches platform to verify AI activity across enterprise systems 20d ago MELBOURNE, Fla., June 30, 2026, CyberNewswire – OpenMatter Network today announced the launch of its cryptographically verifiable platform for secure collaboration and AI governance, built on a simple premise: Don't Trust Data. Prove It. ... News alert: SpyCloud report finds phishing surge exposing employee data at Fortune 100 companies 32d ago AUSTIN, Tex., June 17, 2026, CyberNewswireŌĆōSpyCloud, the leader in identity threat protection, today released its 2026 Phishing Pulse Report, revealing that phishing attacks continue to increase in both volume and sophistication for enter... News alert: Heimdal study finds executives are more confident than frontline IT teams on AI risk 33d ago LONDON, June 17, 2026, CyberNewswire–Heimdal today published The State of AI Risk Management in 2026, a survey of 1,000 IT professionals across the United Kingdom and the United States. The report's headline finding is a divide inside the...
34 loaded
PF
KO
Krebs on Security
5d ago · 10 items
Microsoft Patches a Record 570 Security Flaws 5d ago Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesd... Lessons Learned from CISA’s Recent GitHub Leak 7d ago The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almos... Felons, Fraudsters Flog Offensive Cybersecurity Startup 12d ago A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intellige... FBI Seizes NetNut Proxy Platform, Popa Botnet 17d ago The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technolo... Scattered Spider Hackers Plead Guilty on Day 1 of Trial 27d ago Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The ... ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm 32d ago For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers ... Who Runs the Ransomware Group ‘The Gentlemen?’ 40d ago A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of... A Record-Breaking Patch Tuesday for June 2026 40d ago Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bug... Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts 49d ago The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how ... Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks 56d ago Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the Euro...
DB
David Bombal
6d ago · 15 items
15 loaded
BF
Blog – Forter
6d ago · 10 items
PN
Proofpoint News Feed
6d ago · 10 items
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials 6d ago Hackers find a new trick to collect Microsoft Entra user data without raising red flags 7d ago Suspected Chinese snoops caught breaking into universities' Roundcube mailservers 12d ago Proofpoint researcher tells The Reg: 'We estimate the total volume of targets would be a few dozen' New Cargo Theft Surge: From Lobster Heists To Bourbon Warehouse Scams 19d ago Cargo theft is evolving with cybercrime. Learn how organized crime is hijacking shipments—from a $400,000 lobster theft to a $500,000 bourbon heist—and what needs to be done. Defending the Authentication Flow: Device Code Phishing with Selena Larson 20d ago Host Caleb Tolin sits down with Selena Larson, Staff Threat Researcher and Lead, Intelligence Analysis and Strategy at Proofpoint and Host of the DISCARDED podcast, to discuss the mechanics of device code phishing and the widespread abuse o... Proofpoint Joins the OpenAI Daybreak Cyber Partner Program to Advance Responsible AI-Powered Cyber Defense 28d ago Proofpoint has been selected to participate in OpenAI Daybreak, which helps trusted cybersecurity companies integrate AI into defensive security operations. Through the OpenAI Daybreak Cyber OpenAI Lets Cyber Vendors Embed GPT-5.5 in Defenses 28d ago Suspected North Korean actors use fake ‘coding assignments’ to steal crypto 41d ago China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa 46d ago Proofpoint Introduces Active Exploits Protection to Help Organizations Prioritize Vulnerability Patching for Real-World Attacks in the AI Era 54d ago New solution reduces exposure to actively exploited vulnerabilities in minutes by turning intelligence into immediate protection across primary attack paths Disrupts AI-powered exploit-
WE
WeLiveSecurity
6d ago · 20 items
20 loaded
WE
WeLiveSecurity
6d ago · 48 items
Forgotten UEFI shims undermining Secure Boot 6d ago ESET Threat Report H1 2026 12d ago Cyber readiness for SMBs: Getting the basics right 17d ago This month in security with Tony Anscombe – June 2026 edition 20d ago Inside the inbox: Why cybercriminals want to break into your email account 21d ago SMB cyber readiness: the road to resilience starts here 24d ago Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances 25d ago ESET takes part in Operation Endgame to disrupt Amadey and Stealc 26d ago Killing me gently: Inside Gentlemen’s EDR killer framework 32d ago Protecting legacy OT systems against modern cyberthreats 33d ago
48 loaded
NA
NahamSec
7d ago · 15 items
15 loaded
TC
The Cyber Mentors
10d ago · 15 items
15 loaded
CY
CyberScoop
10d ago · 130 items
Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail 10d ago Interpol cybercrime crackdown nets 5,800 arrests across 97 countries 11d ago 764 splinter group leader sentenced to 40 years in jail 11d ago French nonprofit starts global intelligence and research hub for AI cyber threats 11d ago Found fast, fixed slow: The gap the AI clearinghouse must close 12d ago Spain arrests suspected hacker linked to Russian hacktivist campaign 12d ago Deepfake CSAM lawsuit against xAI, Grok expands 12d ago Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities 13d ago Proofpoint researchers said attackers targeted physics and engineering departments, and warn that the campaign is likely ongoing. US Army websites defaced with pro-Kurdish sentiments, insults to Trump 14d ago Sysdig clocks first documented case of agentic ransomware 14d ago
130 loaded
TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry 21d ago From Langflow to Monero: Inside CVE-2026-33017 Cryptominer 27d ago PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM 32d ago Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign 33d ago Governing Claude Enterprise in Environments Where Inline Controls Can't Go 38d ago GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026 40d ago Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open 42d ago Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet 49d ago Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet 55d ago Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware 59d ago
20 loaded
M3
Microsoft 365 Blog
25d ago · 10 items
Copilot in Excel: Built for the era of Frontier Finance 25d ago - Discover how Copilot in Excel transforms finance workflows with skills, data connectors, and capabilities for traceability. Copilot Cowork is now generally available 34d ago Copilot Cowork is now generally available worldwide, bringing secure, AI-powered automation for complex enterprise tasks in Microsoft 365. Introducing Microsoft Scout: Your always-on personal agent 48d ago Microsoft introduces a new, always-on personal agent, Microsoft Scout, integrated across the Microsoft 365 apps you use every day. Announcing the new Work IQ APIs 48d ago Build enterprise agents with Work IQ APIs for Microsoft 365—bringing business context, tools, and secure, scalable intelligence into every workflow. Introducing Microsoft 365 Business with Copilot: The new standard for small business 52d ago Meet Microsoft 365 Business with Copilot—the AI-powered solution transforming how small businesses work, collaborate, and compete. Introducing a new design for Microsoft 365 Copilot 53d ago Copilot’s redesigned experience delivers faster performance, adaptive tools, and clearer AI-powered workflows to help you easily move from intention to outcome. New and improved: Computer-using agents, a new workflows experience, and real-time voice experiences 55d ago Explore what's new in Copilot Studio, May 2026: computer-using agents are now available, plus redesigned workflows and Work IQ extensibility. New and improved: Agent governance, intelligent workflows, and connected app experiences 70d ago See what's new in Copilot Studio, April 2026: updates to workflows, more control over agent operations, and an expanded agent usage estimator. Copilot Cowork: From conversation to action across skills, integrations, and devices 76d ago Today, we’re announcing additional capabilities in Cowork to expand on what it can make possible for you. Microsoft 365 Copilot, human agency, and the opportunity for every organization 76d ago Empower your organization with Microsoft 365 Copilot—AI that bridges human potential and business outcomes for the future of work.
AL
Alerts
32d ago · 44 items
CISA Adds One Known Exploited Vulnerability to Catalog 32d ago CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure 32d ago CISA Adds One Known Exploited Vulnerability to Catalog 34d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog 35d ago CISA Adds One Known Exploited Vulnerability to Catalog 38d ago CISA Adds One Known Exploited Vulnerability to Catalog 39d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog 41d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog 42d ago CISA Adds One Known Exploited Vulnerability to Catalog 45d ago CISA Adds One Known Exploited Vulnerability to Catalog 47d ago CISA has added one new vulnerability to its KEV Catalog, based on evidence of active exploitation.
44 loaded
AC
All CISA Advisories
32d ago · 125 items
Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT 32d ago CISA Adds One Known Exploited Vulnerability to Catalog 32d ago Schneider Electric EasyLogic T150 and Saitel DP 32d ago AVer PTC cameras 32d ago Rockwell Automation FactoryTalk Historian Site Edition 32d ago AzeoTech DAQFactory 32d ago Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products 32d ago Mitsubishi Electric MELSEC iQ-F Series 32d ago Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module 32d ago CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure 32d ago
125 loaded
CY
cybersecurity
39d ago · 1867 items
Any solutions we can use? 39d ago Possible targeted attack 39d ago RoguePlanet: Windows Zero-Day That Weaponizes Defender's Own Quarantine Pipeline 39d ago Facebook messenger to text 39d ago Managing Solution Agents 39d ago Nottingham University data breach affects over 450,000 students 39d ago SWGs that support 3rd party external DNS resolver 39d ago Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers 39d ago Chrome extensions with 10M+ installations are actively vulnerable to UXSS & UXSG 39d ago Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable | TechCrunch 39d ago
1867 loaded
HS
hacking: security in practice
39d ago · 241 items
DIY pwnagotchi-like device on esp32 39d ago Flipper Blackhat + Bjorn 39d ago Do you think AI is making hacking easier or harder 39d ago What can i do left? PSN 39d ago Proxmark5 campaign ending in less than 18 hours. 39d ago How to bypass speed queen coin slot for washer and dryer 39d ago Self-hosting stuff for when things get ugly 39d ago Malware Includes Taboo In Text To Prevent LLM Analysis 39d ago added Mac support for my corporate hacking game, demo on Steam 40d ago Catfished 40d ago
241 loaded
RE
Reverse Engineering
39d ago · 181 items
Reverse engineered BLE protocol of a $7 generic Chinese smart ring from Temu, and built an iOS app around it 39d ago [Reverse-Engineering] Skeet CS:GO source code (Gamesense) 39d ago [Reverse-Engineering] Skeet CS:GO source code (Gamesense) 39d ago Giulio Zausa's MMO-CHIP Makes Reverse Engineering Old Silicon Chips a Multiplayer Game 39d ago I built 99 adversarially malformed PE files to test tool robustness - here’s what happened 39d ago Drive Firmware Security - Phison S11 39d ago IDA 9.4 Beta | Hex-Rays Docs 40d ago Trane Tracer HVAC cybersecurity issues 40d ago 🚀 Release PyMemoryEditor v2.0 — read, write and scan the memory of any running process, in pure Python (Windows, Linux & macOS) 40d ago I reverse engineered Lofree Hypace mouse firmware flashing protocol to bypass their official web based configuration on MacOS. 41d ago
181 loaded
US charges suspected Russian hacker with facilitating cyber campaign 39d ago Hawkish GOP lawmaker Don Bacon says he was hacked by Russia 39d ago Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025 39d ago GreatXML: GreatXML bitlocker bypass vulnerability 39d ago GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan 39d ago I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue 39d ago [Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion 39d ago GhostTrace – CLI forensic scanner for Windows: 22 modules, MITRE ATT&CK mapped, read-only by default 39d ago Miasma-style supply chain attacks 39d ago On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet 39d ago
603 loaded
MA
Malware Analysis & Reports
39d ago · 115 items
I built 99 adversarially malformed PE files to test tool robustness - here’s what happened 39d ago ClickFix attack in the wild — fake Cloudflare CAPTCHA delivering obfuscated PowerShell dropper 40d ago WordPress malware in official WooCommerce theme (Kiosko): hidden admin users and corrupted sitemap 40d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace 40d ago Fake Interview deploys stealthy cross platform (macOS/Windows) through npm package install in take home assessment 42d ago 73 Microsoft GitHub repositories impacted by Miasma malware 42d ago Unauthorized Onlyfans Payment 42d ago Building A Malware Lab From Scratch Part 2! 44d ago Detecting npm Native Addon Malware: node-gyp Abuse 44d ago Microsoft Warns of GPU Cryptojacking Campaign Spread Through AI Chatbot Links 45d ago
115 loaded
SK
STÖK
57d ago · 15 items
15 loaded
DE
DEFCONConference
82d ago · 15 items
15 loaded
13 loaded
AI in Tax Season: Risks, Scams, and How to Protect Your Data 137d ago Tax Season Scams to Watch For This Year 144d ago Beware of Misleading Tax Advice on Social Media 312d ago Each year the IRS educates taxpayers on the most trending fraud schemes that could deceive individuals and businesses during tax season. In late 2024, The IRS took to warning the public against misleading “tips” or... Scammers Up Their Game With AI 313d ago Learn how to spot the threats and protect yourself from scammers using AI for phishing and deepfakes with smart security practices. The Essential Guide to Safeguarding Your Online Passwords 391d ago Protect your personal and business data with strong passwords, two-factor authentication, and smart cybersecurity practices. Beware: Tax Season is Scam Season 502d ago Tax season is also prime time for tax scams. To safeguard your personal information, consider these key points: Communication methods The IRS initiates contact primarily through mail, not email or phone calls. Be cautious of... Stop Scams: Fraud Prevention Starts with Your Employees 515d ago You can be as proactive and protective as possible when it comes to cyber security for your business, but there’s one vulnerability you cannot eliminate: human error. In fact, statistics estimate that as much as... ‘Tis the Season for Holiday Shopping Scams 588d ago The holidays are typically the time of year for gifting presents to friends and family or donations to charity. Unfortunately, not-so-jolly fraudsters take advantage of this generosity. Protect yourself by watching for these common scams:..... IRS Issues “Dirty Dozen” Fraud Warnings 773d ago Each year, the IRS releases a “Dirty Dozen” series to highlight the most common fraud schemes taxpayers should be aware of. IRS Identity Theft Season Begins Now 902d ago Each year thieves try to steal billions in federal withholdings by stealing your identity. As the IRS focuses more attention on this quickly growing problem, now is the time of year to be extra vigilant....
LI
LiveOverflow
137d ago · 15 items
15 loaded
HA
HackerSploit
467d ago · 15 items
15 loaded
TH
Threatpost
1419d ago · 10 items
Student Loan Breach Exposes 2.5M Records 1419d ago 2.5 million people were affected, in a breach that could spell more trouble down the line. Watering Hole Attacks Push ScanBox Keylogger 1420d ago Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool. Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms 1421d ago Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system. Ransomware Attacks are on the Rise 1424d ago Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group. Cybercriminals Are Selling Access to Chinese Surveillance Cameras 1424d ago Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed. Twitter Whistleblower Complaint: The TL;DR Version 1426d ago Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk. Firewall Bug Under Active Attack Triggers CISA Warning 1427d ago CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP. Fake Reservation Links Prey on Weary Travelers 1428d ago Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels. iPhone Users Urged to Update to Patch 2 Zero-Days 1431d ago Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack. Google Patches Chrome’s Fifth Zero-Day of the Year 1432d ago An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.

No matching sources found.