FOE
Bleeping Computer
Amgen says cloud data breach exposed patient health, proprietary info
FOE
Bleeping Computer
Arch Linux disables AUR package adoption to stop malware flood
FOE
Bleeping Computer
Online ad firm Adform’s script compromised to steal cryptocurrency
FOE
Ars Technica (Security)
Claude published malicious code to the Internet and attacked 3 real companies
FOE
EFF Deeplinks
Amending AB 1709 Doesn’t Fix It: California’s Social Media Ban Still Threatens Free Speech and Privacy
FOE
EFF Deeplinks
The SCREEN Act Threatens Privacy Far Beyond Adult Websites
FRIEND
EPIC
Illinois Governor Signs Age-Appropriate Design Code into Law
FOE
EPIC
EPIC Urges FTC to Abandon Misleading Guidance Suggesting Consumer Protection Laws Preempt State AI Regulations
FOE
EFF Deeplinks
The CHATBOT Act Forces One Parenting Model On Every Family
FOE
Bleeping Computer
OpenAI says its new GPT 5.6 models are becoming more cost-efficient
FOE
The Hacker News
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
FRIEND
Dark Reading
CISA Issues Fresh SBOM Guidance. Did They Get It Right?
FOE
Bleeping Computer
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
FRIEND
Schneier on Security
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
FOE
Bleeping Computer
CISA warns of cyberattacks disrupting U.S. water utilities
FOE
The Hacker News
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
FOE
The Register (Security)
The most famous brand in physical security got pwned by ShinyHunters
FOE
CSO Online
DefCon security conference bans smart glasses with recording capabilities
FOE
SecurityWeek
In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
FOE
SecurityWeek
Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers
FOE
The Register (Security)
Anthropic and OpenAI are competing to see whose agents can go rogue harder
FOE
The Hacker News
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
FOE
Ars Technica (Security)
AI scammers outperform humans when it comes to building trust
FOE
Bleeping Computer
ESET tracks rise in malicious AI skills and adaptable malware
FOE
BrightTALK InfoSec
Automating Evidence and Policy Checks for AIOps
FRIEND
Dark Reading
The Morning After We Pull a Root of Trust, Nobody Owns It
FOE
The Register (Security)
Charities remain locked out of CAF Bank online accounts
FOE
CSO Online
Google adds to confusion with new names for threat actors
FOE
CSO Online
Broadcom patches vulnerabilities all over VMware
FOE
Dark Reading
Interpol Leverages Global System to Curtail Fraud Payments
FRIEND
Dark Reading
DROP Platform Lets Californians Reduce Digital Footprint
FOE
CSO Online
Microsoft almost gave away the keys to everyone’s Azure Cosmos DBs
FOE
The Hacker News
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: Thin and wispy
FOE
The Hacker News
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
FRIEND
Pen Test Partners
If you’re going to vibe code it, why not vibe pen test it?
FOE
The Hacker News
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
FOE
The Hacker News
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
FOE
Schneier on Security
Facial Recognition at Madison Square Garden
FOE
CSO Online
JetBrains says a crafted HTTP request could break TeamCity
FOE
SecurityWeek
Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace
FOE
SecurityWeek
EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels
FOE
SecurityWeek
Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations
FRIEND
SANS Internet Storm Center
zipdump.py: Metadata Encoding, (Fri, Jul 31st)
FOE
SecurityWeek
Critical Flaw Led to Azure Cosmos DB Pwnage
FOE
CSO Online
After OpenAI, Anthropic finds Claude breached three organizations during cyber tests
FRIEND
CSO Online
5 key priorities for your Black Hat agenda — and what to avoid
FOE
SecurityWeek
CareCloud Data Breach Impacts Over 350,000
FOE
SecurityWeek
Critical Code Execution Vulnerability Patched in TeamCity
FOE
The Hacker News
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
FOE
Risky Business News
Risky Bulletin: Non-profit offers $22,000 bounty for INC ransomware group
FOE
The Register (Security)
Anthropic’s Claude escaped test sandbox to attack three organizations
FOE
CSO Online
Copilot worm can spread through Microsoft Word docs
FOE
CSO Online
Microsoft confirms an AI worm is propagating through Copilot and other MS apps
FOE
Bleeping Computer
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
FOE
Sophos News
When AI doesn’t know the target is real
FRIEND
Sophos News
Three-headed dogs and long tails: Sophos at BSides LV
FOE
Bleeping Computer
South Korea fines telco giant KT $39 million for customer data breach
FOE
SecurityWeek
CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
FOE
Bleeping Computer
JetBrains warns of critical TeamCity remote code execution flaw
FOE
CSO Online
A coordinated attack hit 30+ Minnesota water systems. Who did it, and what does a Rockwell notice add to the picture?
FOE
Dark Reading
Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
FRIEND
SecurityWeek
Bank of America to Acquire Cybersecurity Firm MDSec
FOE
Ars Technica (Security)
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
FOE
Dark Reading
AI Harnesses Burst With Potential Exploit Opps
FRIEND
SecurityWeek
Okta to Acquire Identity Threat Detection Firm Permiso
FOE
The Hacker News
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
FOE
Bleeping Computer
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
FOE
Bleeping Computer
VMware fixes three critical flaws allowing auth bypass, VM escapes
FRIEND
Bleeping Computer
Google says AI helped Chrome fix 1,072 security bugs in two releases
FOE
Krebs on Security
Read This Before You Buy That TV Streaming Stick
FOE
Bleeping Computer
ShinyHunters claims Brinks Home breach, threatens to leak stolen data
FOE
Schneier on Security
American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials
FOE
Bleeping Computer
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
FRIEND
SecurityWeek
Timeless Compliance: Why Better Questions Beat Bigger Frameworks
FOE
Dark Reading
Claude Mythos — Hype vs. Reality: What Security Teams Need to Know
FOE
The Hacker News
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
FOE
Bleeping Computer
Analog Devices discloses data breach, says operations unaffected
FRIEND
Professor Messer
Today’s SY0-701 CompTIA Security+ Pop Quiz: I didn’t see you there
FOE
EPIC
PRESS RELEASE: Challenge to DOGE’s Unlawful Seizure of Payment System Data Advances
FOE
Bleeping Computer
After the Break-In: What Attackers Do Once They're Already Inside
FRIEND
SecurityWeek
DataBahn Raises $40 Million for Agentic Data Pipeline Management
FOE
The Hacker News
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
FRIEND
SecurityWeek
Discern Security Raises $13 Million in Series A Funding
FRIEND
SecurityWeek
Cantina Emerges From Stealth With $8 Million in Funding
FOE
CSO Online
AI agents gain access to financial workflows amid growing governance gaps
FOE
CSO Online
Critical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridge
FRIEND
SecurityWeek
Onyx Security Raises $113 Million to Control AI Agents in the Enterprise
FOE
SecurityWeek
‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: I brought treats
FOE
CISA Alerts
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
FOE
CISA Alerts
MikroTik RouterOS
FOE
CISA Alerts
NASA Core Flight System (cFS) Health & Safety (HS) Application
FOE
CISA Alerts
Watchfire Controller Software
FOE
CISA Alerts
Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
FOE
CISA Alerts
MZ Automation lib60870
FOE
CISA Alerts
Toptech Systems RCU II+ and Multiload II+
FOE
CISA Alerts
Schneider Electric IGSS
FOE
CISA Alerts
Johnson Controls OpenBlue Employee
FOE
CISA Alerts
MZ Automation GmbH libiec61850
FOE
CISA Alerts
o6 Automation open62541
FOE
CISA Alerts
Mitsubishi Electric CC-Link IE TSN Communication Protocol
FRIEND
CISA Alerts
Open Source Software: Security Principles and Practices
FOE
The Hacker News
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
FRIEND
The Hacker News
The Network Has Become the Control Plane for AI Security
FOE
SecurityWeek
Semiconductor Firm Analog Devices Discloses Data Breach
FOE
Schneier on Security
Should You Use AI for a Task? Here’s a Simple Way to Decide
FOE
CSO Online
Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover
FOE
The Hacker News
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
FOE
The Hacker News
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
FOE
The Register (Security)
Russian spies take their half-click email attack from Zimbra to Outlook
FOE
SecurityWeek
Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms
FOE
SecurityWeek
1 in 5 Data Center Assets Are Within Easy Reach of Attackers
FOE
CSO Online
A Scattered Spider member was indicted. Microsoft’s GDID went to trial.
FRIEND
SecurityWeek
US and Allies Update SBOM Guidance
FRIEND
SecurityWeek
Chrome 151 Patches 370 Vulnerabilities
FOE
The Hacker News
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
FOE
The Hacker News
FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
FOE
Risky Business News
Srsly Risky Biz: Chipping Away at Chinese AI Risks
FOE
The Register (Security)
Headteacher had the most guessable username-password combo you could imagine
FOE
SecurityWeek
Cisco Secure FMC Zero-Day Exploited in the Wild
FOE
The Register (Security)
Excuses like 'AI did it' don't exist in the eyes of the law
FOE
The Hacker News
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
FOE
The Hacker News
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
FOE
Dark Reading
SE Asian Cybercriminal Syndicates Become a Global Power
FRIEND
CSO Online
CISA unveils a six-step blueprint for isolating critical infrastructure during cyberattacks
FOE
SANS Internet Storm Center
Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th)
FOE
Dark Reading
'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China
FOE
Bleeping Computer
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
FRIEND
Dark Reading
Cybersecurity, Then & Now
FOE
Ars Technica (Security)
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
FOE
Bleeping Computer
Anthropic confirms Claude is down worldwide
FOE
Bleeping Computer
Cisco warns of FMC static credential flaw exploited in zero-day attacks
FOE
Dark Reading
OpenAI's Rogue Model Claims More Victims Beyond Hugging Face
FRIEND
Dark Reading
Red Agents vs. Blue Agents: How to Make AI Better At Defense
FOE
The Register (Security)
Closed models refuse to help researcher swat Linux bug
FOE
The Hacker News
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
FOE
Bleeping Computer
Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
FOE
Dark Reading
Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions
FOE
Dark Reading
Hugging Face Hack Lessons for Cyber Defenders
FOE
Schneier on Security
Measuring the Tendency of AI Agents to Go Rogue
FOE
Dark Reading
When AppSec Scanners Become a Supply Chain Attack Vector
FOE
EFF Deeplinks
🏃 Fitness Tracker Privacy Fails | EFFector 38.14
FOE
The Register (Security)
Word worm crawls into Copilot, spreads chaos
FOE
Bleeping Computer
OpenAI agent used exposed credentials at 4 services in Hugging Face breach
FOE
SpecterOps
Clustered Points of Failure
FOE
Ars Technica (Security)
Anthropic is finding bugs faster than Microsoft can fix them
FOE
The Hacker News
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
FOE
The Hacker News
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
FOE
CSO Online
Mythos takes its first shot at post-quantum cryptography
FRIEND
CSO Online
Sweet Security Brings Autonomous Protection to the AI Enterprise with New Blocking Capabilities
FOE
Bleeping Computer
Hackers target over 30 Minnesota water utilities in coordinated OT attack
FOE
Dark Reading
Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms
FOE
EPIC
The Christian Science Monitor: A US agency listed an AI immigration tool online. The disclosure vanished after our inquiry.
FOE
Bleeping Computer
Your AI Agents Are Guessing at Scale: Permissions Decide the Damage
FRIEND
Black Hills Information Security
Report As You Go: Maintaining Good Documentation for SOC Analysts
FRIEND
Bleeping Computer
Windows 11 KB5101684 update released with 42 changes and fixes
FOE
The Register (Security)
Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems
FOE
The Hacker News
Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
FOE
The Hacker News
Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
FOE
SecurityWeek
US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security
FOE
CSO Online
OpenAI rogue AI agent’s attack expanded beyond Hugging Face
FRIEND
SecurityWeek
Mate Security Raises $35 Million for Agentic SOC
FRIEND
SecurityWeek
ThreatLocker Raises $190 Million in Series F Funding
FOE
The Hacker News
Mythos Asks the Right Question. It Doesn't Answer It.
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: I left them on the table
FOE
CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog
FRIEND
CISA Alerts
2026 Minimum Elements for a Software Bill of Materials (SBOM)
FOE
The Hacker News
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
FOE
SecurityWeek
Critical VM Escape Vulnerability Patched in VMware ESXi
FOE
The Hacker News
73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
FOE
Schneier on Security
Long-Lived Vulnerability in Microsoft Secure Boot
FOE
The Hacker News
Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
FRIEND
SecurityWeek
US, Australia Release OT Isolation Guidance for Critical Infrastructure
FOE
SecurityWeek
OpenAI’s Rogue AI Ventured Beyond Hugging Face
FOE
CSO Online
It’s easier to steal cargo than toothpaste
FRIEND
SecurityWeek
Spur Raises $200 Million for IP Intelligence Platform
FOE
CSO Online
Risk-based patching is the future. AI made it table stakes
FOE
The Hacker News
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
FOE
SecurityWeek
JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
FRIEND
CSO Online
How MFA gets hacked — and strategies to prevent it
FOE
SecurityWeek
Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
FOE
The Hacker News
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
FRIEND
SANS Internet Storm Center
Apple Patches Everything (July 2026), (Wed, Jul 29th)
FOE
CSO Online
Ransomware report: VPNs in the crosshairs, AI attacks
FOE
The Hacker News
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
FOE
The Hacker News
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
FOE
Risky Business News
Risky Bulletin: New Chinese cyber contractor identified
FOE
SecurityWeek
ShinyHunters Claims Ernst & Young Hack
FOE
The Hacker News
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
FOE
The Register (Security)
America bans imported robots due to supply chain and security risks
FOE
Schneier on Security
Measuring LLMs’ Ability to Perform Cryptanalysis
FRIEND
CSO Online
Fortinet’s new FortiGate platform converges firewall, SASE technologies
FOE
CSO Online
A 13-year-old flaw is exposing tens of thousands of data center management systems
FOE
CSO Online
The CSO’s blind spot: Why platform engineering 2.0 is now a security imperative
FOE
CSO Online
Arista patches maximum severity vulnerability that is already being exploited
FOE
CISA KEV
CVE-2026-20316: Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
FRIEND
Sophos News
Secure by Design in practice: a year of progress on Sophos Firewall
FOE
The Register (Security)
JFrog's 0-days let OpenAI's models hack Hugging Face
FOE
The Register (Security)
Looks like JFrog's 0-days let OpenAI's models hack Hugging Face
FOE
EFF Deeplinks
San Francisco: Don’t Fall for Industry Defense of Surveillance Pricing
FOE
Ars Technica (Security)
We now have a better understanding how OpenAI hacked into Hugging Face
FOE
Dark Reading
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
FOE
Bleeping Computer
CubePilot drone software dev hit by DNS hijacking to intercept traffic
FOE
Dark Reading
Flaw From 2002 Exposes Data Centers to Server Takeover
FOE
Bleeping Computer
OpenAI models used Artifactory zero-days to escape to the internet
FOE
Dark Reading
When AI Agents Escape Sandboxes, Old Security Rules Apply
FRIEND
Dark Reading
Stronger AI Safety Requires Peeking Inside the 'Black Box'
FRIEND
The Register (Security)
Microsoft and Wiz mind-meld agents catch more than 90% of bugs
FOE
The Hacker News
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
FRIEND
Bleeping Computer
CISA shares advice on isolating vital systems during cyberattacks
FOE
Bleeping Computer
vBulletin fixes critical pre-auth RCE flaw with public exploit
FOE
Dark Reading
'Certighost' Flaw Haunts Microsoft Active Directory Certificates
FOE
EFF Deeplinks
Why Are Gay Bars Building Databases of Their Patrons?
FRIEND
The Register (Security)
DEF CON bans Meta-style 'pervert glasses'
FOE
The Register (Security)
AI-found bugs aren't proving any easier to exploit despite the hype
FOE
The Hacker News
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
FRIEND
Professor Messer
Today’s N10-009 CompTIA Network+ Pop Quiz: I’ll take a number 4
FRIEND
SecurityWeek
Cyera Acquiring Oasis Security in $1 Billion Deal
FOE
The Hacker News
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
FOE
EPIC
CNET: The Government’s Indictment of an Activist Tests Whether You Have a Right to Wipe Your Phone
FOE
EPIC
BBC: How period trackers share your private details
FOE
SecurityWeek
Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe
FOE
Bleeping Computer
Is Your SSO Protected Against Modern Credential Attacks?
FOE
The Register (Security)
Bank for charities pulls online services over security fears
FOE
The Register (Security)
Charity bank pulls online services over third-party software flaw
FOE
The Hacker News
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
FRIEND
SecurityWeek
OT Security Startup Frenos Raises $1.52 Million
FRIEND
CSO Online
Infoblox joins crowded EASM market with DNS-centric approach
FOE
The Hacker News
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
FOE
The Register (Security)
Uncle Sam needs you to fight for 6G leadership and security, lest Beijing get there first
FRIEND
Dark Reading
Former Citigroup CISO Blauner on What Makes A Great Security Leader
FOE
Bleeping Computer
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: We’re fresh out
FRIEND
CISA Alerts
CI Fortify – Advice for isolating vital systems
FOE
CISA Alerts
igloohome Smart Lock Mobile Application
FOE
CISA Alerts
MikroTik RouterOS and Cloud Hosted Router
FOE
CISA Alerts
Siemens Mendix Runtime
FOE
CISA Alerts
Siemens SIMATIC S7-PLCSIM Advanced
FOE
CISA Alerts
Siemens Desigo CC
FOE
CISA Alerts
ABB KNX Update Tool
FOE
CISA Alerts
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
FOE
SpecterOps
Introducing Attack Path Management for Entra Agents in BloodHound Enterprise
FOE
The Hacker News
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
FRIEND
SpecterOps
Attack Path Management Comes to AWS
FRIEND
SpecterOps
Designing an MCP Server for AI Agents: Why Wrapping Your API Is the Wrong Abstraction
FOE
SpecterOps
Expanding attack path management to the AI frontier
FRIEND
SecurityWeek
Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model
FOE
Schneier on Security
Axon Is Another License Plate Surveillance Company
FOE
SecurityWeek
Act Security Emerges from Stealth to Fight the Patch Problem
FRIEND
SecurityWeek
Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker
FRIEND
SecurityWeek
Hush Security Raises $30 Million for AI Agent Governance
FOE
The Register (Security)
Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
FOE
Bleeping Computer
Data breach at medical billing firm MCBS affects 1.26 million people
FOE
CSO Online
Why your AI safety certificates are worthless at runtime
FRIEND
SecurityWeek
Google Adopts New Threat Actor Naming System
FOE
The Hacker News
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
FOE
The Hacker News
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
FOE
CSO Online
Hugging Face breach shows why incident response needs a multi-model AI strategy
FOE
SANS Internet Storm Center
AutoIT Payload Injector , (Tue, Jul 28th)
FOE
SecurityWeek
Unpatched Fastjson Vulnerability Exploited in Attacks
FOE
SecurityWeek
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
FRIEND
The Hacker News
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
FOE
SecurityWeek
Origin Energy Data Breach Affects 900,000 Australians
FOE
The Hacker News
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
FOE
TrustedSec
AI Directives and AI Strategy Development
FOE
CSO Online
Hackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accounts
FOE
SecurityWeek
For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startup
FRIEND
CSO Online
Microsoft unveils multi-model agentic cyber stack for security operations
FOE
CSO Online
Samsung’s AI-powered glasses could be looking at your data
FOE
CSO Online
Samsung’s entry into AI-powered glasses forces CISOs to again consider corporate risk
FOE
Dark Reading
AI Agent Drives Espionage Attack on Thai Ministry of Finance
FOE
Sophos News
Chaos in Teams vishing
FOE
Bleeping Computer
Hackers target US firms in FastJson RCE zero-day attacks
FOE
Bleeping Computer
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
FRIEND
Ars Technica (Security)
Microsoft unveils AI security tools it says outperform competing platforms
FOE
Dark Reading
Agentic Browsers Rewind Web Security by 20 years
FOE
Bleeping Computer
New Dysphoria DDoS botnet spreads to 200k devices worldwide
FOE
Bleeping Computer
New Certighost PoC exploit lets attackers hijack Windows domains
FOE
Dark Reading
'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure
FOE
EPIC
EPIC and CDT Urge FCC to Reconsider Invasive Know Your Customer Rulemaking Proposal
FOE
Dark Reading
FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
FRIEND
The Register (Security)
Microsoft's solution to AI security: more AI and more acronyms
FRIEND
EFF Deeplinks
Missed EFF's Livestream with Adam Savage and iFixit? Listen Here!
FOE
Dark Reading
Why Resetting Passwords No Longer Stops Attackers
FRIEND
The Hacker News
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
FOE
Dark Reading
Adversaries Don't Need a Zero-Day — They Read Your Rulebook
FOE
Bleeping Computer
Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin
FOE
The Hacker News
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
FOE
The Register (Security)
Tech giants link hands to praise open AI models after OpenAI - Hugging Face attack
FOE
BrightTALK InfoSec
Securing AI Agent Reasoning Against Logic-Layer Attacks in 90 Days
FOE
Ars Technica (Security)
Activist charged with felony after giving border agent "duress code" that wiped his phone
FOE
Bleeping Computer
Coca-Cola confirms data theft in Fairlife ransomware attack
FOE
Bleeping Computer
Ernst & Young data breach claimed by ShinyHunters extortion gang
FOE
The Hacker News
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
FRIEND
SecurityWeek
New GitHub, PyPI Policies Boost Supply Chain Security
FOE
The Hacker News
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
FOE
Bleeping Computer
Shadow AI agents are multiplying. Here's how to find and secure them.
FOE
The Register (Security)
Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update
FOE
SecurityWeek
PTC Windchill Vulnerability Exploited in Ransomware Campaign
FOE
The Hacker News
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
FOE
SecurityWeek
MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection
FOE
The Hacker News
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
FRIEND
SecurityWeek
Nvidia and Tech Giants Launch AI Security Alliance
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: It sounds super
FOE
CISA Alerts
CISA Adds Two Known Exploited Vulnerabilities to Catalog
FOE
CSO Online
Certighost haunts Microsoft Active Directory Certificate Services
FOE
SecurityWeek
Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack
FRIEND
CSO Online
OpenAI not part of the new Open Secure AI Alliance
FRIEND
SecurityWeek
Beelzebub Raises $3.4 Million for Hacker-Trapping Platform
FOE
Schneier on Security
Cognyte Sells a Mobile Cell Surveillance Van
FRIEND
SecurityWeek
What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out
FOE
The Hacker News
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
FOE
SecurityWeek
Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials
FOE
SANS Internet Storm Center
Java Spring Boot "heapdump" scans, (Mon, Jul 27th)
FRIEND
SecurityWeek
Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits
FOE
CSO Online
The containment paradox: Why your ransomware playbook has the wrong people in charge
FOE
SecurityWeek
DentaQuest Data Breach Potentially Impacts Over 23 Million People
FOE
CSO Online
When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk
FOE
The Hacker News
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
FRIEND
The Hacker News
GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
FRIEND
The Register (Security)
Google goes it alone with a new cybercrime crew taxonomy
FRIEND
CSO Online
How CISOs can rise to the business resilience challenge
FOE
Risky Business News
Risky Bulletin: A JSON RCE bug is about to rock the Java world
FOE
SecurityWeek
MCBS Data Breach Affects 1.2 Million Individuals
FRIEND
Sophos News
Why Sophos Has Become Its Own AI Test Lab
FRIEND
Sophos News
Turn cybersecurity into a high-value business function with Sophos CISO Advantage
FOE
CISA KEV
CVE-2026-16812: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
FOE
CISA KEV
CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
FRIEND
Sophos News
Introducing Sophos AI Defense
FOE
SANS Internet Storm Center
Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)
FRIEND
Bleeping Computer
GitHub, PyPI add time-absed defenses against supply chain attacks
FOE
Bleeping Computer
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
FOE
The Hacker News
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
FOE
Bleeping Computer
Malicious sites use JavaScript to build malware in browser memory
FOE
Bleeping Computer
ShinyHunters data leaks fuel $2,000 sextortion email scam
FOE
The Hacker News
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
FOE
The Hacker News
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
FOE
The Hacker News
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
FOE
The Hacker News
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
FOE
Bleeping Computer
OpenAI confirms ChatGPT is down worldwide
FOE
The Hacker News
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
FOE
SecurityWeek
Rockwell Patches Code Execution Flaws in Arena Simulation Software
FOE
The Register (Security)
Pope's official prayer app commits cardinal sin, leaks 700K+ users' info
FRIEND
Dark Reading
CISOs vs. Boards: Myth or Misunderstanding?
FOE
The Register (Security)
Europol flags 4,340 'horrific' URLs linked to The Com
FOE
Bleeping Computer
OnTrac notifies customers of data breach after network hack
FOE
Dark Reading
Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
FOE
Bleeping Computer
Hermes AI agent used to automate attack on Thai Finance Ministry
FOE
EPIC
PRESS RELEASE: Privacy Rights Advocates Challenge Trump-Vance Administration’s Secret Tracking of People Exercising their First Amendment Rights
FOE
Bleeping Computer
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
FOE
Bleeping Computer
Microsoft blames massive Microsoft 365 outage on maintenance bug
FOE
The Hacker News
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
FOE
SecurityWeek
In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
FOE
The Hacker News
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
FOE
Bleeping Computer
Chick-fil-A data breach affects more than 13,000 customers
FOE
Bleeping Computer
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
FOE
Dark Reading
Vatican's Official Prayer App Leaks 700K+ Global Users' PII
FOE
Bleeping Computer
Europol flags 4,340 URLs for removal in 'The Com' crackdown
FOE
Dark Reading
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
FOE
The Register (Security)
Uncle Sam tells overseas cybercrooks their visas are canceled
FRIEND
SecurityWeek
AegisAI Raises $36 Million for AI-Powered Email Security
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: There’s a bit of an echo
FOE
The Hacker News
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
FOE
The Hacker News
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
FOE
The Hacker News
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
FOE
SecurityWeek
Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday
FOE
Bleeping Computer
Man gets six years for hacking 750 women's Snapchat accounts
FRIEND
Schneier on Security
Why AI Needs a “Genie Coefficient”
FOE
CSO Online
Top AIs invent same fake PyPl and npm package names
FOE
CSO Online
Tycoon2FA takedown reshapes the phishing landscape
FOE
The Hacker News
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
FOE
The Hacker News
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
FOE
The Hacker News
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
FOE
Bleeping Computer
Clop ransomware targets Windchill, FlexPLM in data theft attacks
FOE
Dark Reading
Europe's Multilingual Reality Exposes AI Security Gaps
FOE
CSO Online
Ransomware groups are hammering your vulnerable VPNs
FOE
The Hacker News
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
FOE
The Hacker News
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
FOE
SecurityWeek
Data Breach Confirmed After Australian Energy Giant Origin Is Hacked
FRIEND
TrustedSec
CCPA Update: Cybersecurity Requirements (Part 2)
FOE
Risky Business News
Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers
FOE
CSO Online
AgentForger proves AI agents can become persistent insider threats
FOE
The Register (Security)
OpenAI-Hugging Face attack doesn't mean agents are evil – unless you tell them to be
FOE
The Register (Security)
Researchers replace downloaded macOS apps with evil twins, Apple shrugs
FOE
EFF Deeplinks
Hundreds of Drone-as-First-Responder Programs Could Soon Be Launched Across the Country
FOE
Dark Reading
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
FOE
Bleeping Computer
New Dolphin X malware uses AI to rank high-value targets
FOE
CSO Online
Check Point hole grants unauthenticated attackers full SmartConsole admin privileges
FOE
Bleeping Computer
Australian energy provider Origin says data breach exposes client data
FOE
Bleeping Computer
Fake Claude app promoted by Bing ads pushes SectopRAT malware
FOE
CSO Online
4 ways AI-driven defense is rewriting the cybersecurity playbook
FOE
The Intercept (Privacy)
Trump’s Crypto Corruption Puts Centrist Democrats in Bind
FOE
The Hacker News
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
FOE
Bleeping Computer
Russian hackers exploit Zimbra zero-click flaw for email theft
FOE
The Register (Security)
Year-long Russian attacks infect users as soon as they look at an email
FOE
Bleeping Computer
Hackers abuse Notepad++ plugins to stealthily install malware
FOE
The Register (Security)
Millions of California-bought cars can be hijacked via Bluetooth
FOE
CSO Online
Linux XFS has a decade-old race condition allowing full root access
FOE
Bleeping Computer
Microsoft 365 outage affects Teams, SharePoint and other services
FOE
The Register (Security)
Oracle drops 1,449 security patches like it's the new normal
FOE
SecurityWeek
OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider
FOE
The Hacker News
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
FRIEND
Professor Messer
Today’s SY0-701 CompTIA Security+ Pop Quiz: Lemonade to go
FOE
SecurityWeek
Is Patching Dead? Vulnerability Management in the Post-Mythos Era
FOE
SecurityWeek
Chick-fil-A Accounts Get Fried in Credential Stuffing Attack
FOE
The Register (Security)
Iran-linked crews are probing more flavors of US industrial kit
FRIEND
Bleeping Computer
FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires
FRIEND
SecurityWeek
Abstract Raises $25 Million to Expand Composable Security Operations Platform
FOE
SANS Internet Storm Center
When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)
FOE
The Hacker News
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
FOE
The Hacker News
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
FOE
The Register (Security)
One ChatGPT link could smuggle a rogue AI agent into your company
FOE
SecurityWeek
Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models
FOE
Bleeping Computer
EU fines Google $1 billion for search, app store antitrust violations
FRIEND
The Register (Security)
If you get knocked on the head and get all your devices stolen and have amnesia, Google will let you back in with a selfie
FOE
The Hacker News
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: I’ll get the hammer
FOE
CISA Alerts
MZ Automation lib60870
FOE
CISA Alerts
Johnson Controls XAAP Android
FOE
CISA Alerts
MZ Automation libIEC61850
FOE
CISA Alerts
Weintek cMT3092X
FOE
CISA Alerts
Panduit IntraVUE
FOE
CISA Alerts
Johnson Controls C-CURE 9000 and Victor application server
FOE
CISA Alerts
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
FOE
The Register (Security)
Swiss train maker tells ransomware crooks to get off at the next stop
FOE
The Hacker News
How Synthetic Identity Fraud is Coming for Machine Identities
FOE
Bleeping Computer
New RefluXFS Linux flaw lets attackers gain root privileges
FOE
The Hacker News
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
FOE
Dark Reading
Agentic AI Challenges Progress in Confidential Computing
FOE
Schneier on Security
End-to-End Encryption and “Going Dark”
FOE
SecurityWeek
Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses
FRIEND
The Hacker News
Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
FOE
Bleeping Computer
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
FRIEND
SecurityWeek
Assaf Keren Appointed New CISO of Meta
FOE
Bleeping Computer
Microsoft working to fix Exchange Online mailbox quarantine issue
FOE
SecurityWeek
New Check Point Zero-Day Vulnerability Exploited in the Wild
FOE
Bleeping Computer
Check Point warns of SmartConsole zero-day exploited in attacks
FOE
The Hacker News
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
FOE
Risky Business News
Srsly Risky Biz: Knives Are Out For Open-Weight AI Models
FOE
The Register (Security)
Talking smack about a doctor got him access to private medical files
FOE
Dark Reading
Brazilian Banking Trojan Actively Spreading in Portugal
FOE
CSO Online
Microsoft’s 3-day patching directive comes with added operational risk
FOE
The Hacker News
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
FOE
SecurityWeek
US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices
FOE
Dark Reading
Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain
FOE
Sophos News
When the "attacker" is an AI agent
FOE
Dark Reading
Flaws in Passkey Implementation Show Old Attacks Still Work
FOE
CSO Online
German law enforcement claims to have ‘dismantled’ mega phishing-as-a-service group Kratos
FOE
The Register (Security)
OpenAI scored an own goal with Hugging Face attack, showing how open Chinese models are winning
FOE
The Register (Security)
OpenAI scored an own goal with HuggingFace attack, showing how open Chinese models are winning
FOE
EFF Deeplinks
The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required
FRIEND
Professor Messer
Professor Messer’s SY0-701 Security+ Study Group – July 2026
FOE
Bleeping Computer
Upbound says hack caused $13 million in fraudulent Acima leases
FOE
Dark Reading
Attackers Are Learning to Live Off the AI Toolchain
FOE
CSO Online
Critical Zimbra security update fixes 9 vulnerabilities
FOE
Bleeping Computer
South Korea discloses data breach impacting diplomats worldwide
FOE
Dark Reading
Fake Bahrain Alert App Deploys Android Surveillance Malware
FOE
The Hacker News
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
FOE
CSO Online
Oracle’s July update fixes ten 10.0 vulnerabilities in Fusion Middleware
FOE
The Hacker News
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
FOE
SANS Internet Storm Center
Rondo Meets Geoserver, (Wed, Jul 22nd)
FOE
Bleeping Computer
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
FOE
The Register (Security)
Linux kernel team publishes 432 CVEs in two days
FOE
Ars Technica (Security)
OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face
FRIEND
CSO Online
Cisco’s new AI model tells code reviewers where to look for vulnerabilities
FOE
Dark Reading
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
FOE
Bleeping Computer
How enterprise GenAI can amplify ransomware risk — and how to contain it
FOE
SecurityWeek
Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts
FOE
The Hacker News
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
FRIEND
SecurityWeek
Palo Alto Networks to Acquire Observability Platform Provider Embrace
FOE
SecurityWeek
Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft
FRIEND
Bleeping Computer
New InfraTrust report reveals infrastructure flaws admins should patch first
FRIEND
TCM Security Blog
TCM Academy Course Release: Windows Evidence Acquisition and Triage
FRIEND
Black Hills Information Security
The Life of a SOC Analyst: Responsibilities, Challenges, and Strategies for Success
FOE
SecurityWeek
When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover
FOE
CSO Online
OpenAI model escape puts enterprise AI defenses on notice
FOE
Bleeping Computer
Adobe Chrome extension flaw let sites access private WhatsApp chats
FOE
The Register (Security)
Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits
FRIEND
SecurityWeek
StrongestLayer Raises $4.1 Million in Seed Funding Extension
FOE
SecurityWeek
Vibe-Coded Apps Riddled With Exploitable Security Flaws
FOE
The Hacker News
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: How quaint
FOE
CISA Alerts
CISA Adds Two Known Exploited Vulnerabilities to Catalog
FRIEND
The Hacker News
The Fastest Path to AI Adoption Runs Through Security
FOE
The Register (Security)
Greedy ransomware crews return for seconds after victims cough up first extortion payments
FOE
Bleeping Computer
CISA orders urgent action on actively exploited Langflow RCE flaw
FOE
Dark Reading
EU Financial Institutions Leak Data Through Cookie Trackers
FOE
SecurityWeek
Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks
FOE
The Hacker News
Why Modern SOCs Need Multi-Layered Detections
FOE
Schneier on Security
First-Person Identity Theft Story
FOE
Bleeping Computer
Microsoft to stop Exchange 2016 / 2019 security updates in October
FRIEND
SecurityWeek
Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation
FRIEND
SecurityWeek
Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
FOE
CSO Online
AI, security operations and the new race against time
FOE
EFF Deeplinks
New EU Court of Justice Ruling on Platform Liability Could Cause Collateral Damage to Freedom of Expression
FOE
SecurityWeek
Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife
FOE
The Register (Security)
Council worker spared prison after four-day data-snooping spree
FOE
SecurityWeek
OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face
FRIEND
CSO Online
10 survival tips for CSOs who report to the CEO
FOE
Bleeping Computer
Chick-fil-A discloses data breach after credential stuffing attacks
FOE
The Hacker News
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
FOE
Risky Business News
Risky Bulletin: Linux kernel discloses 442 CVEs as AI bugpocalypse settles in
FOE
The Hacker News
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
FOE
Bleeping Computer
OpenAI says its AI models hacked Hugging Face during testing
FOE
The Hacker News
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
FOE
The Hacker News
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
FOE
The Register (Security)
OpenAI admits it was the source of the agent swarm that attacked Hugging Face
FOE
Krebs on Security
LG to Ban Residential Proxies from Smart TV Apps
FOE
CISA KEV
CVE-2026-50522: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
FOE
CISA KEV
CVE-2026-16232: Check Point SmartConsole Improper Authentication Vulnerability
FRIEND
Bleeping Computer
Police dismantle Kratos phishing platform, arrest developer
FOE
Bleeping Computer
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
FOE
Dark Reading
Ransomware Is Accelerating, But It's Not Because of AI
FOE
Dark Reading
Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task
FRIEND
The Register (Security)
Cisco's open-weight bug busters take on Google and OpenAI
FOE
Bleeping Computer
Critical SharePoint RCE flaw exploited to steal machine keys
FOE
The Register (Security)
AI's cheatin' heart will make you weep
FOE
EPIC
PRESS RELEASE: EPIC and the National Institute for Workers’ Rights Release White Paper on Algorithmic Unionbusting
FOE
Bleeping Computer
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
FOE
The Hacker News
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
FOE
Dark Reading
Hacker Turns AI Jailbreaks Into Offensive Attack Platform
FRIEND
SecurityWeek
Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains
FRIEND
BrightTALK InfoSec
Reduce AI Risk with Threat Intelligence–Driven SecOps
FRIEND
SecurityWeek
Cisco Launches Low-Cost AI Models for Source Code Security
FOE
Bleeping Computer
Critical wp2shell WordPress flaws exploited to install webshells
FOE
The Register (Security)
Kratos phishing-as-a-service kit loses its battle with international law enforcement
FOE
The Hacker News
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
FRIEND
BrightTALK InfoSec
Optimizing SOC Defense with Emerging Tech for the AI Era
FRIEND
The Hacker News
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
FRIEND
Professor Messer
Today’s N10-009 CompTIA Network+ Pop Quiz: The rainbow of cables
FOE
The Hacker News
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
FOE
The Hacker News
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
FOE
Bleeping Computer
Closing the Identity Gaps in Critical Infrastructure Security
FOE
The Register (Security)
AI music platform Suno hits bum note as 55M users exposed in data breach, claims infosec expert
FRIEND
SANS Internet Storm Center
Captive Portal Detection, (Tue, Jul 21st)
FOE
Ars Technica (Security)
Apps targeted at US troops contain Chinese and Russian code
FOE
The Hacker News
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
FRIEND
The Register (Security)
Intel fortifies Foundry with an actual customer: Fortinet
FOE
Dark Reading
Choose Wisely: AI-Generated Coding Risk Varies, A Lot
FRIEND
SecurityWeek
Empirical Security Raises $25 Million in Series A Funding
FRIEND
SecurityWeek
SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: Looks good to me
FOE
CISA Alerts
Rockwell Automation ThinManager
FOE
CISA Alerts
Rockwell Automation 1734 POINT I/O
FOE
CISA Alerts
Rockwell Automation 1718-AENTR/1719-AENTR
FOE
CISA Alerts
Siemens Opcenter X
FOE
CISA Alerts
Rockwell Automation FactoryTalk Services Platform
FOE
CISA Alerts
Tycon Systems TPDIN-Monitor-WEB2
FOE
CISA Alerts
Siemens IAM Client
FOE
CISA Alerts
Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
FOE
CISA Alerts
Rockwell Automation Studio 5000 Logix Designer
FOE
CISA Alerts
Siemens CADRA
FOE
CISA Alerts
Siemens SIDIS Secured SmartPlug
FOE
CISA Alerts
CISA Adds Four Known Exploited Vulnerabilities to Catalog
FOE
The Hacker News
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
FOE
SecurityWeek
New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
FOE
CSO Online
AI agents can escape sandboxes without ever breaking them
FOE
The Hacker News
N-day is Becoming N-Hour. Patching Faster Won't Save You.
FRIEND
SecurityWeek
CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG
FOE
The Hacker News
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
FOE
SecurityWeek
Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
FOE
Schneier on Security
MIT to Become Hotbed of AI Video Surveillance
FOE
Bleeping Computer
US seizes over 1,000 websites in FIFA World Cup piracy crackdown
FOE
SecurityWeek
Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data
FOE
Bleeping Computer
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
FOE
SecurityWeek
Clover Health Investments Discloses Data Breach
FOE
Bleeping Computer
Microsoft shares manual fix for WSUS sync delays and timeouts
FOE
The Hacker News
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
FOE
SecurityWeek
Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
FOE
SecurityWeek
Zimbra Update Patches Critical Vulnerabilities
FOE
Bleeping Computer
Windows LegacyHive zero-day flaw gets free, unofficial patches
FOE
The Hacker News
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
FOE
CSO Online
White hat hacker Park Chan-am zeros in on the AI era’s key security challenges
FRIEND
CSO Online
Context bombing heralds a new AI era of deceptive defense
FOE
The Hacker News
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
FOE
The Register (Security)
OVH reveals semi-secret plan to fix critical Januscape hypervisor bug with mass reboots – and an Australian crash-test dummy
FOE
The Register (Security)
OVH reveals semi-secret plan to fix critical Januscape bug with mass reboots – and an Australian crash-test dummy
FOE
Sophos News
July Patch Tuesday only feels endless
FRIEND
Sophos News
Sophos Named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services for Midmarket 2026
FOE
CISA KEV
CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
FOE
CISA KEV
CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability
FOE
CISA KEV
CVE-2026-60137: WordPress Core SQL Injection Vulnerability
FOE
Bleeping Computer
Estée Lauder discloses data breach via Oracle E-Business flaw
FOE
Bleeping Computer
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
FOE
Bleeping Computer
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
FOE
The Register (Security)
Attackers pummel critical WordPress vuln to create all sorts of mischief
FRIEND
EFF Deeplinks
Protect Your Privacy with California's DROP Tool
FOE
Dark Reading
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
FOE
Bleeping Computer
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
FOE
Bleeping Computer
JadePuffer agentic attacks now target AI model data with ransomware
FOE
EPIC
Section 230 Does Not Immunize App Stores for Selling Illegal Casino Chips, EPIC Tells 9th Circuit
FRIEND
Dark Reading
Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push
FOE
CSO Online
ServiceNow’s sandbox escape RCE hole now exploited in the wild
FOE
The Register (Security)
Scammers impersonate FBI on social media, prey on crime victims
FOE
The Intercept (Privacy)
U.S. Official: Iran Attacks Injured “Far More” Troops Than Pentagon Admits
FOE
Dark Reading
25 Years After Code Red: What the Worm Era Can Teach Us About AI Security
FOE
EFF Deeplinks
An Explosion of Surveillance Towers is Coming to U.S. Borders, Costing Over $1 Billion
FOE
The Register (Security)
Malicious cloud customers can bring down the power grid
FOE
Dark Reading
CISOs Feel the Heat Over AI Risk
FRIEND
EFF Deeplinks
“Stealth Crawlers” Are Not a Threat to the Open Web. Bills Targeting Them Would Be.
FOE
The Register (Security)
Frontier LLMs couldn't help Hugging Face fight off evil agents
FOE
SANS Internet Storm Center
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
FOE
Dark Reading
Attackers Combo Up Evasion Tactics for BEC Phishing
FOE
The Hacker News
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
FOE
Bleeping Computer
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
FOE
The Hacker News
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
FRIEND
BrightTALK InfoSec
Preparing Security Analysts for the Reality of Modern Security Operations
FOE
The Register (Security)
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
FRIEND
SecurityWeek
Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software
FOE
CSO Online
AI adoption and business acceleration are changing the expectations of technology risk management
FOE
The Hacker News
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
FOE
SecurityWeek
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
FRIEND
Bleeping Computer
An AI SOC Evaluation Guide for Security Leaders
FOE
Ars Technica (Security)
Pay up or not? Ransomware surge has victims facing tough choices
FRIEND
Dark Reading
Cybersecurity Keeps Events 'Uneventful'
FOE
The Hacker News
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
FOE
SecurityWeek
OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability
FOE
CSO Online
Patch now: WordPress REST API bug allows remote code execution
FOE
The Hacker News
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
FOE
CSO Online
New ACR Stealer campaigns use WebDAV, MSHTA to evade detection
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: A work of art
FOE
Bleeping Computer
Hugging Face discloses breach linked to autonomous AI agent
FOE
SecurityWeek
New Index Tracks Material Breaches — And Refuses to Add Up the Losses
FOE
The Hacker News
Mythos Didn't Break Your Security Program. Your Exposure Window Could.
FOE
SecurityWeek
Ernst & Young Data Breach Affects Personal, Financial Information
FOE
Schneier on Security
On Flock License Plate Tracking Cameras
FOE
Bleeping Computer
Microsoft confirms Windows Server Update Services sync delays
FRIEND
SecurityWeek
Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
FRIEND
Bleeping Computer
Windows KB5121767 OOB update fixes shutdowns on some Dell PCs
FOE
The Intercept (Privacy)
Google Is Censoring Reviews of ICE Detention Centers
FOE
SecurityWeek
Hugging Face Hacked in Autonomous AI Attack
FOE
Bleeping Computer
Critical ServiceNow code execution flaw now exploited in attacks
FOE
The Hacker News
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
FOE
The Hacker News
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
FOE
The Intercept (Privacy)
Hegseth’s War Department Slashed Civilian Protection Staff, Brought in AI Assessments
FOE
SecurityWeek
Chrome 150 Update Patches Severe Memory Safety Bugs
FOE
CSO Online
SOCs face a human challenge as AI speeds alerts and threats
FRIEND
CSO Online
Claude Mythos FAQ: Capabilities, access, competitors, implications
FOE
Risky Business News
Risky Bulletin: Hacker wipes Romania's entire land registry database
FOE
The Hacker News
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
FOE
SecurityWeek
WP2Shell WordPress Vulnerabilities Exploited in the Wild
FOE
The Hacker News
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
FRIEND
Sophos News
Sophos ZTNA unlocks SaaS app control and so much more
FOE
Sophos News
In code we trust? Why the most trusted software receives the least scrutiny.
FRIEND
Sophos News
Sophos joins Anthropic's Project Glasswing
FOE
The Hacker News
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
FOE
The Register (Security)
Connecting AI agents to outside services explodes the risk radius
FOE
SANS Internet Storm Center
Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)
FOE
Bleeping Computer
Hackers abuse ViPNet software to target Russian govt agencies
FOE
The Hacker News
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
FOE
The Hacker News
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
FOE
Bleeping Computer
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
FOE
Bleeping Computer
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
FOE
Bleeping Computer
Microsoft warns of surge in ACR Stealer attacks on customers
FRIEND
Bleeping Computer
The Future of Age Verification: Your Face Never Leaves Your Device
FOE
The Hacker News
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
FOE
Bleeping Computer
Abbott Laboratories probes two cyber incidents amid extortion claims
FRIEND
Professor Messer
Professor Messer’s N10-009 Network+ Study Group – July 2026
FOE
The Hacker News
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
FOE
Dark Reading
Inc Ransomware Exploits SonicWall SMA Zero-Days
FOE
The Hacker News
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
FRIEND
BrightTALK InfoSec
From Vendors to Digital Workers: Verifying Trust in the Agentic Supply Chain
FOE
Bleeping Computer
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
FRIEND
CSO Online
OnlyFans performers become unlikely allies of CISOs in securing websites
FOE
The Hacker News
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
FRIEND
EFF Deeplinks
Victory! Flock Ends Rollout of Audio “Distress Detection” of Human Voices
FRIEND
EFF Deeplinks
Your Vision. Your Legacy. Your Future.
FOE
Dark Reading
The Real AI Threat Is Blind Trust
FOE
The Hacker News
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
FOE
The Register (Security)
AI spam filters are getting suckered by old-school text salting
FOE
BrightTALK InfoSec
Scaling Operational Resilience Against AI-Driven Threats
FRIEND
EFF Deeplinks
How the Watch Dogs Video Game Series Mirrored and Predicted Real-World Digital Rights Issues
FOE
Bleeping Computer
Ernst & Young discloses data breach after support system hack
FOE
CSO Online
Google must open Android to rival AI agents, EU orders
FOE
SecurityWeek
In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint
FOE
Bleeping Computer
Inside the Search for "Clean" Residential Proxies for Carding
FOE
The Hacker News
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
FRIEND
Dark Reading
Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear
FOE
SecurityWeek
Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: Maybe you should lay down
FOE
The Register (Security)
Attackers target critical FortiSandbox flaws as CISA issues patch order
FRIEND
Dark Reading
Google Bets 'Agentic Defense' Strategy Can Outpace Attackers
FOE
The Hacker News
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
FRIEND
SecurityWeek
Beacon Security Raises $13 Million for Security Data Platform
FOE
The Hacker News
The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?
FRIEND
SecurityWeek
Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday
FOE
Bleeping Computer
New Windows LegacyHive zero-day gives hackers admin privileges
FRIEND
Schneier on Security
Details of Alan Turing’s Voice Encryption System
FOE
The Hacker News
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
FOE
The Register (Security)
Google fixing Android lock screen bug that lets Gemini send SMS without a PIN
FOE
Bleeping Computer
Windows Server 2022 reach end of mainstream support in 90 days
FOE
SecurityWeek
Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei
FOE
CSO Online
The SaaS blind spot: Why security teams can’t get inside their own apps
FOE
The Hacker News
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
FOE
The Hacker News
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
FOE
CSO Online
Fake TTF files deliver stealthy malware in global phishing campaign
FRIEND
SecurityWeek
Risk Ledger Raises $32 Million in Series B Funding
FOE
Bleeping Computer
US charges two over laundering $43 million from investment fraud
FOE
SecurityWeek
Fresh SharePoint Vulnerability Exploited Soon After Disclosure
FOE
Bleeping Computer
CISA urges immediate action on actively exploited Fortinet flaws
FOE
CSO Online
Senior executives are killing your shadow AI strategy
FOE
The Hacker News
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
FOE
SecurityWeek
Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack
FRIEND
The Register (Security)
South Korea making its own security-centric AI model
FOE
The Register (Security)
OpenAI admits GPT-5.6 occasionally deletes files – but it's an 'honest mistake'
FOE
Bleeping Computer
New ClickLock macOS malware traps users into revealing login password
FOE
Bleeping Computer
Coca-Cola says Fairlife ransomware attack halts US dairy production
FOE
Dark Reading
Agentic AI Is Untamable: Ask the Right Security Questions
FOE
EPIC
PRESS RELEASE: Coalition Asks Federal Court to Enforce Landmark Ruling Blocking Unlawful SAVE System
FOE
The Register (Security)
Researcher poisons open-weight AI model for under $100
FOE
Dark Reading
1M+ Emails Use Hidden Text to Dupe AI Security Filters
FOE
Ars Technica (Security)
Now, even Russia's most elite hackers are using Clickfix to infect devices
FOE
Bleeping Computer
Claude Chrome extension flaw lets malicious extensions trigger AI actions
FOE
Bleeping Computer
New OkoBot framework deploys 20 payloads to steal data, crypto
FOE
The Intercept (Privacy)
ICE Officers at Maine Shooting Scene Were Wearing Body Cameras. They Were Not Turned On.
FOE
CSO Online
Zoom patches account takeover hole
FOE
The Hacker News
Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack
FOE
The Hacker News
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
FOE
The Register (Security)
C'mon, just copy this text string and paste it into your macOS Terminal – it'll fix your computer, honest
FOE
SecurityWeek
Legacy Systems, Real-World Impacts: The Reality of OT Security
FRIEND
Professor Messer
Today’s SY0-701 CompTIA Security+ Pop Quiz: I’m very familiar
FRIEND
Schneier on Security
Protecting Privacy in an AI Era
FOE
Bleeping Computer
AI Agents Broke the Security Playbook. Here's What Replaces It.
FOE
Bleeping Computer
23andMe to pay $18 million in new genetics data breach settlement
FOE
The Hacker News
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
FOE
SecurityWeek
Two Scattered Spider Hackers Sentenced to Jail in UK
FOE
SecurityWeek
AI Data Centers Are Being Built Faster Than They Can Be Secured
FOE
The Hacker News
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
FOE
The Register (Security)
Brit Scattered Spider duo handed tickets to prison over Transport for London attack
FOE
SecurityWeek
‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
FOE
The Hacker News
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
FOE
Bleeping Computer
Scattered Spider members behind TfL hack get five years in prison
FOE
CSO Online
CISA urges immediate SharePoint hardening as exploits mount
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: The map is not working
FOE
CISA Alerts
CISA Adds Three Known Exploited Vulnerabilities to Catalog
FOE
CISA Alerts
NASA Core Flight System (cFS) Health & Safety (HS) Application
FOE
CISA Alerts
SALTO ProAccess Space
FOE
CISA Alerts
Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
FOE
CISA Alerts
Rockwell Automation Flex 5000 Adapter
FOE
CISA Alerts
Rockwell Automation FactoryTalk DataMosaix
FOE
CISA Alerts
Rockwell Automation Arena
FOE
CISA Alerts
Siemens SICAM 8
FOE
CISA Alerts
Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix
FOE
CISA Alerts
AutomationDirect Productivity Suite
FOE
Bleeping Computer
Windows 11 24H2 Home and Pro reach end of support in 90 days
FOE
The Hacker News
20+ Hijacked Government Websites Became
an Attack Channel
FOE
The Hacker News
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
FOE
The Register (Security)
Windows 10 refuses to die, and the security bill is coming due
FRIEND
SecurityWeek
Oak Emerges From Stealth Mode With $60 Million in Funding
FOE
The Hacker News
Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor
FOE
Bleeping Computer
CISA orders feds to patch actively exploited Oracle flaw by Saturday
FOE
SecurityWeek
Splunk, Zoom Patch Critical Vulnerabilities
FRIEND
CSO Online
CISA urges software vendors to formalize vulnerability disclosure programs
FOE
Bleeping Computer
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
FRIEND
The Hacker News
AI Can Find Bugs, But Human Knowledge Still Proves Them
FOE
The Register (Security)
Telegram shortlinks knocked offline over sanctioned VPN connection
FOE
Bleeping Computer
New Spirals ransomware encrypts victim network in under 24 hours
FOE
CSO Online
When AI gets a body, it inherits an attack surface
FOE
The Hacker News
Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide
FOE
EFF Deeplinks
EFF and ARTICLE 19 Submission to the European Commission on the DSA Trusted Flagger Guidelines
FOE
SecurityWeek
F5 Patches Multiple NGINX, BIG-IP Vulnerabilities
FOE
CSO Online
The executive profile your security team isn’t defending
FOE
SecurityWeek
China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans
FRIEND
The Hacker News
OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol
FOE
SecurityWeek
Old UEFI Shims Expose Systems to Secure Boot Bypass
FOE
Risky Business News
Srsly Risky Biz: Ransomware Uses AI To Amp Up Negotiations
FOE
The Hacker News
Zoom Patches Critical Windows Flaw That Could Enable Account Takeover
FOE
The Register (Security)
Law firm insisted on one password to rule them all
FOE
Dark Reading
Police Disrupt a €140M Cyber Fraud Ring in Spain
FOE
CSO Online
Flaw surge fuels need for CISOs to rethink vulnerability management
FOE
SecurityWeek
Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day
FOE
The Register (Security)
Tech support scam caused massive data breach at Australian airline Qantas
FOE
SecurityWeek
Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities
FOE
The Register (Security)
Cyberattack threatens utterly critical infrastructure in Japan: KFC
FOE
CISA KEV
CVE-2026-58644: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
FOE
CISA KEV
CVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerability
FOE
Bleeping Computer
Dutch police bust investment fraud ring stealing over €100 million
FOE
Dark Reading
Forgotten Bootloaders Expose Secure Boot Blind Spot
FOE
EFF Deeplinks
California Steps Back From Dangerous Expansion of its Age-Gating Law
FOE
CSO Online
NPM ecosystem hit with two new supply chain compromises
FOE
Dark Reading
Identity Attacks Overtake Exploits as Top Ransomware Cause
FOE
Bleeping Computer
Zoom warns of critical account takeover vulnerability
FOE
Ars Technica (Security)
Windows 0-day drops the same day Microsoft releases record number of patches
FOE
EFF Deeplinks
Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features
FOE
The Hacker News
TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
FOE
Bleeping Computer
Google Gemini CLI abused as a hacking agent, malware botnet operator
FRIEND
Dark Reading
Guten Tag, Bonjour, Hola to Our European Cyber Defenders!
FOE
The Intercept (Privacy)
Intel Pick Jay Clayton Won’t Tell Congress Whether Trump Ordered Subpoenas of NYT Journalists
FOE
EPIC
EPIC Seeks Records on USDA’s Secretive Palantir Contracts Meant to Detect SNAP Fraud
FOE
Dark Reading
Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife
FOE
EFF Deeplinks
🚫 Don't Let Congress Age-Gate the Internet | EFFector 38.13
FOE
Bleeping Computer
AsyncAPI npm packages infected with credential-stealing malware
FOE
The Hacker News
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
FOE
Dark Reading
Claude Flaw Automatically Sends Malicious Prompts to AI Agents
FOE
The Register (Security)
CISA sounds alarm over trio of exploited SharePoint flaws
FOE
EPIC
EPIC Again Urges USDA to Abandon Proposed National SNAP Database That Threatens Privacy
FOE
SecurityWeek
Unpatched Cursor Vulnerability Exposes Users to Code Execution
FOE
SecurityWeek
CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities
FOE
Bleeping Computer
We built a vulnerability vending machine: AI tokens in, zero-days out
FRIEND
Black Hills Information Security
KAPE 101: A Kroll Artifact Parser and Extractor Cheatsheet
FOE
The Register (Security)
Microsoft cancels Patch Tuesday for some Dell users over surprise shutdowns, overheating devices
FOE
The Hacker News
Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
FOE
Dark Reading
2-Click Cursor Exploit Enables Dev Environment Takeover
FOE
SecurityWeek
Windows Bind Link Attacks Can Hide Malware From EDR Tools
FOE
CSO Online
New Windows Bind Link techniques let attackers evade EDR, security controls
FOE
The Register (Security)
LegacyHive: 'Bone-shattering' zero-day from Microsoft's serial tormentor not the haymaker that was promised
FRIEND
SecurityWeek
Virtual Event Today: Cloud & Data Security Summit
FRIEND
CSO Online
White House launches AI-driven vulnerability clearinghouse to speed cyber remediation
FOE
CSO Online
New bugs in Claude for Chrome allow extensions to abuse AI privileges
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: Clap on
FOE
CISA Alerts
CISA Adds Two Known Exploited Vulnerabilities to Catalog
FRIEND
CISA Alerts
Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers
FOE
SecurityWeek
US Charges Russian Individuals and Firms for Running Cybercrime Services
FOE
The Hacker News
SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.
FOE
The Hacker News
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
FRIEND
The Hacker News
New Webinar: Closing the Approval Gap in AI-Era Ad Tech
FOE
Schneier on Security
A Video Screen That Is Also a Camera
FOE
SecurityWeek
Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow
FOE
The Hacker News
Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution
FRIEND
SecurityWeek
White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative
FOE
CSO Online
When 80,000 fans log on at once: The 2026 World Cup’s unique cybersecurity issues
FOE
SecurityWeek
Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption
FOE
Bleeping Computer
CISA warns admins to patch actively exploited SharePoint flaws
FOE
SecurityWeek
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell
FOE
The Hacker News
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
FOE
CSO Online
Cybersecurity needs more prevention and less reliance on cure
FOE
Bleeping Computer
Microsoft: Some Dell PCs shut down after recent Windows updates
FOE
Dark Reading
Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits
FOE
Bleeping Computer
US charges alleged operators of Russian bulletproof hosting service
FOE
SecurityWeek
Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
FRIEND
CSO Online
7 skills and traits of elite security engineers
FOE
The Hacker News
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
FOE
SecurityWeek
SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits
FRIEND
CSO Online
Microsoft is forcing an enterprise transition to passkeys
FOE
CSO Online
Patch Tuesday roundup: Microsoft fixes a monthly record 569 holes; SAP patches a critical memory corruption bug
FRIEND
SANS Internet Storm Center
Recent DShield SIEM Update, (Tue, Jul 14th)
FRIEND
Dark Reading
Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal
FOE
Sophos News
SonicWall SMA1000 vulnerabilities in active exploitation
FOE
CISA KEV
CVE-2026-46817: Oracle E-Business Suite Improper Privilege Management Vulnerability
FOE
CISA KEV
CVE-2023-4346: KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
FRIEND
Sophos News
The stack had a good run. Defense systems are the future.
FOE
Sophos News
The State of Ransomware 2026: Payments are dropping but encryption is climbing
FOE
Ars Technica (Security)
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
FOE
Dark Reading
Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes
FOE
Bleeping Computer
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
FRIEND
EFF Deeplinks
European Court: Apple Can Not Shirk Off its Interoperability Requirements
FOE
The Register (Security)
Patchpocalypse Now: Microsoft tops last month's record with 622 Patch Tuesday CVEs
FOE
The Hacker News
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
FOE
Bleeping Computer
Spanish Police take down €140 million cyber fraud ring, arrest four
FOE
Dark Reading
6 GHz Wi-Fi Flaws Could Disrupt Critical Systems
FOE
EFF Deeplinks
Don’t Repeat NY’s 3D Printing Blunder
FOE
Krebs on Security
Microsoft Patches a Record 570 Security Flaws
FOE
Bleeping Computer
Nearly 300 GitHub repos pose as legit software to push malware
FOE
SANS Internet Storm Center
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
FOE
SecurityWeek
Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days
FRIEND
Bleeping Computer
Microsoft releases Windows 10 KB5099539 extended security update
FOE
SecurityWeek
Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims
FOE
The Hacker News
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
FOE
Bleeping Computer
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
FRIEND
Dark Reading
Manage Vendor Risk in a Few Practical Steps
FRIEND
Bleeping Computer
Windows 11 KB5101650 & KB5099414 cumulative updates released
FOE
The Hacker News
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
FOE
SecurityWeek
Adobe Patches Critical ColdFusion Vulnerabilities
FOE
The Hacker News
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
FOE
The Register (Security)
Welsh Doxbin admin jailed for egging on swatters from behind a screen
FOE
Bleeping Computer
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
FRIEND
Schneier on Security
Upcoming Speaking Engagements
FOE
Dark Reading
Frontier AI: The Genie's Out of the Bottle, but Where's the Rulebook?
FOE
Dark Reading
ClickFix's Mushrooming Ecosystem Demands New Defense Tactics
FOE
Bleeping Computer
LastPass, Bitwarden users targeted with fake security alerts
FRIEND
Professor Messer
Today’s N10-009 CompTIA Network+ Pop Quiz: I’ll fix it on the screen
FRIEND
Bleeping Computer
You Don't Have to Run an Exploit to Know If You're Vulnerable
FOE
SecurityWeek
7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
FOE
The Hacker News
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
FOE
Dark Reading
Cursor IDE Auto-Executes Malicious Code in Poisoned Repos
FOE
SecurityWeek
Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar
FRIEND
Bleeping Computer
Microsoft Entra ID gets passkeys default authentication starting September
FOE
Bleeping Computer
New phishing kits target Microsoft 365 accounts, evade MFA
FOE
The Hacker News
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
FOE
The Register (Security)
Musk promises purge after Grok Build caught sending entire repos to the cloud
FOE
The Register (Security)
'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: Recreating from scratch
FOE
CISA Alerts
CISA Adds Four Known Exploited Vulnerabilities to Catalog
FOE
CISA Alerts
CISA Urges SharePoint Hardening After New Exploitations
FOE
CISA Alerts
Rockwell Automation 1715-AENTR EtherNet/IP Adapter
FOE
CISA Alerts
ABB Ability Edgenius
FOE
CISA Alerts
ABB Advant Master Online Builder
FOE
CISA Alerts
ABB T-MAC Plus
FOE
The Hacker News
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
FOE
Bleeping Computer
SAP warns of critical flaws in NetWeaver and Commerce Cloud
FRIEND
The Hacker News
How Pentera Turns AI Security Workflows into Validation Engines
FOE
The Hacker News
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
FOE
SecurityWeek
SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud
FOE
Schneier on Security
Vulnerability in FIFA’s Network
FOE
The Register (Security)
Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websites
FOE
SecurityWeek
US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers
FOE
CSO Online
Phishing for dummies: Forg365 lowers barrier to M365 account takeovers
FOE
Bleeping Computer
US sanctions VPN, malware providers for enabling ransomware attacks
FRIEND
SecurityWeek
Valarian Raises $50 Million for Sovereign Infrastructure Control Layer
FOE
SecurityWeek
Multiple Jscrambler Packages Impacted by Supply Chain Attack
FOE
The Hacker News
Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads
FOE
CSO Online
AI incidents need a new playbook. Here’s how to build one
FOE
The Hacker News
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
FOE
The Hacker News
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
FOE
CSO Online
AI-powered breaches provide wake-up call for incident response
FRIEND
SecurityWeek
Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules
FOE
The Hacker News
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
FOE
CSO Online
Governments to enterprises: Improve your router security hygiene
FOE
CSO Online
US authorities warn of Russian attacks on critical infrastructure
FRIEND
Sophos News
Sophos Protected Browser Extension: Protection and visibility without changing browsers
FOE
CISA KEV
CVE-2026-56164: Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
FOE
CISA KEV
CVE-2026-56155: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
FOE
CISA KEV
CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
FOE
Dark Reading
Weak Security Continues to Fuel Russian Cyberattacks
FOE
Ars Technica (Security)
The US government warns that Russia state hackers are coming after your router
FOE
Bleeping Computer
Japan's largest taxi operator shuts systems after cyberattack
FOE
Bleeping Computer
Hackers backdoor Jscrambler npm package with infostealer malware
FOE
Bleeping Computer
New CrashStealer malware poses as Apple crash reporting tool
FOE
Dark Reading
'Yellow Teams' Are Defining the Future of AI Security
FRIEND
EPIC
EPIC Urges D.C. Council to Strengthen Proposed Government Data Privacy and Protection Act
FOE
The Hacker News
CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
FOE
EFF Deeplinks
Sony Nerfs Videogame Ownership
FOE
The Hacker News
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
FOE
Dark Reading
GigaWiper Lets Threat Actors Choose Their Own Destructive Attack
FOE
The Register (Security)
EU and UK officially blame Russian spies for cyberattack on Poland's power grid
FOE
Bleeping Computer
CISA warns of actively exploited RCE flaws in Joomla extensions
FRIEND
Ars Technica (Security)
Now, defenders are embracing the prompt injection, too
FOE
The Hacker News
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
FOE
Krebs on Security
Lessons Learned from CISA’s Recent GitHub Leak
FRIEND
SecurityWeek
Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption
FOE
Bleeping Computer
Lidl discloses online shop breach after service provider hack
FRIEND
Bleeping Computer
Breach at the Beach: Play the Ultimate Entra ID CTF
FRIEND
BrightTALK InfoSec
The Five-Layer Stack Behind Every Defensible AI System
FOE
The Hacker News
New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email
FRIEND
EPIC
EPIC, CFA, Fairplay Submit Recommendations Ahead of Potential Rulemaking for Colorado Automated Decision-Making and Chatbot Laws
FOE
Bleeping Computer
UK charges suspects linked to Russian Coms call spoofing platform
FOE
The Hacker News
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
FRIEND
Dark Reading
Turning the Tables on Email Scammers With 'ScamBuster'
FRIEND
SecurityWeek
Cybersecurity M&A Roundup: 37 Deals Announced in June 2026
FOE
The Register (Security)
World Cup grudge attackers may have scored Argentine FA access via year-old infostealer infection
FOE
CSO Online
RabbitMQ flaws expose OAuth secrets, risk complete takeover of the broker
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: Many colors to choose from
FOE
CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog
FOE
CISA Alerts
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
FOE
SecurityWeek
RabbitMQ Vulnerability Threatens Enterprise Systems
FOE
The Hacker News
Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling
FRIEND
The Hacker News
Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots
FOE
Bleeping Computer
EU sanctions Russian GRU military hackers over cyberattacks
FOE
The Hacker News
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory
FOE
Schneier on Security
AI Data Centers and the Concentration of Wealth
FOE
The Register (Security)
Progress orders emergency ShareFile server shutdown over mystery security threat
FOE
SecurityWeek
Zimbra Patches Critical Code Execution Vulnerability
FOE
SecurityWeek
EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign
FOE
CSO Online
Jurassic Park, cybersecurity and the dangerous myth of control
FOE
Bleeping Computer
US and allies warn of Russian critical infrastructure attacks
FOE
SecurityWeek
Organizations Warned of Exploited Joomla Extension Vulnerabilities
FOE
CSO Online
Your AI risk register is not an incident response plan
FOE
SecurityWeek
Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns
FOE
SecurityWeek
Centers Laboratory Data Breach Affects 540,000 Individuals
FOE
The Hacker News
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
FOE
CSO Online
Can AI narrow cybersecurity’s class divide?
FOE
The Hacker News
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
FOE
SANS Internet Storm Center
Someone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th)
FOE
Bleeping Computer
OpenAI temporarily relaxes GPT-5.6 Sol usage limits
FRIEND
Sophos News
Sophos Firewall v22 MR2 is now available
FOE
CISA KEV
CVE-2008-4128: Cisco IOS Cross-Site Request Forgery Vulnerability
FOE
Bleeping Computer
Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time
FOE
Bleeping Computer
RedHook Android malware now uses Wireless ADB for shell access
FOE
The Intercept (Privacy)
Company That Bragged It Could Track U.S. Spies Hired to Investigate “Havana Syndrome”
FOE
The Hacker News
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
FOE
The Hacker News
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
FOE
SecurityWeek
Ghost Accounts Abuse GitHub API in Mass Recon Campaign
FOE
Bleeping Computer
Australia warns of global campaign targeting vulnerable CMS platforms
FRIEND
SANS Internet Storm Center
Wireshark 4.6.7 Released, (Sat, Jul 11th)
FOE
Bleeping Computer
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
FOE
The Hacker News
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
FOE
Bleeping Computer
New U-Boot flaws could enable stealthy firmware attacks
FOE
Schneier on Security
Friday Squid Blogging: “Squidbleed” Vulnerability
FOE
Dark Reading
Frontier AI: The Genie's Out of the Bottle, But Where's the Rulebook?
FRIEND
Dark Reading
Jen Ellis: Connecting Cyber Community With Political Machinery
FOE
Bleeping Computer
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
FOE
The Register (Security)
Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package
FOE
The Hacker News
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
FOE
Dark Reading
Cybercriminals Flock to Healthcare Businesses as Attacks Surge
FOE
Bleeping Computer
Police suspects Dutch hackers were involved in Odido breach
FOE
The Hacker News
URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
FOE
Bleeping Computer
Progress urges ShareFile admins to shut down servers over “credible” threat
FOE
The Hacker News
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
FOE
Bleeping Computer
Hackers exploit critical auth bypass in Gitea Docker image
FOE
Bleeping Computer
Money launderer accused of stealing seized crypto while in prison
FOE
SecurityWeek
In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops
FRIEND
EFF Deeplinks
Building Our Future Together
FOE
The Hacker News
Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched
FOE
CSO Online
EU extends mass scanning of messages without a warrant
FOE
CSO Online
CrowdStrike identifies five new prompt injection threats to AI
FOE
The Hacker News
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
FOE
Bleeping Computer
The Replicant in Your Directory: AI Agents and the Identity Security Gap
FOE
Dark Reading
Fresh ATM Crypto Software Bugs: Jackpot or Bust?
FOE
Dark Reading
More Countries Jump on the Social Media Ban Wagon
FRIEND
EPIC
PRESS RELEASE: EPIC Applauds Introduction of Privacy-Centered Federal Chatbot Bill
FOE
EFF Deeplinks
Automated Moderation Is Here to Stay—Accountability Must Keep Pace
FOE
The Hacker News
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
FOE
Dark Reading
AI Coding: Do Security Risks Outweigh Productivity Gains?
FOE
SecurityWeek
Third US Security Expert Sentenced to Prison for Helping Ransomware Gang
FOE
The Register (Security)
Fashion mart Miinto unzips breach details, warns shoppers to watch for phisherfolk
FOE
CISA Alerts
CISA Adds Two Known Exploited Vulnerabilities to Catalog
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: A keyboard with two keys
FOE
SecurityWeek
China, India-Linked Hackers Both Targeted Same Pakistani Police Force
FOE
The Hacker News
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
FOE
Bleeping Computer
Zimbra urges customers to patch critical web client XSS flaw
FRIEND
The Hacker News
From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale
FOE
The Hacker News
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
FOE
SecurityWeek
Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers
FOE
Schneier on Security
AI Surveillance and Social Progress
FOE
The Hacker News
Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking
FOE
The Hacker News
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
FOE
The Register (Security)
Scot NHS Trust probes email stuffup involving maternity patients' data
FOE
SecurityWeek
GigaWiper Combines Multiple Malware for System-Level Sabotage
FOE
SANS Internet Storm Center
"Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th)
FOE
The Hacker News
Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets
FOE
CSO Online
The business case for burning down security debt: A practical approach for CISOs
FOE
CSO Online
Microsoft uncovers GigaWiper, a backdoor designed for destruction on demand
FOE
SecurityWeek
‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism
FOE
Bleeping Computer
Former ransomware negotiator gets 4 years for BlackCat attacks
FOE
The Hacker News
Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks
FOE
SecurityWeek
Network of 200 GitHub Repositories Used for Malware Infection
FOE
CSO Online
Check Point CTO Jonathan Zanger sees AI elevating the value of cyber
FOE
Risky Business News
Risky Bulletin: India bans app used to hack e-rickshaws in viral videos
FOE
The Register (Security)
Microsoft warns customers AI will mean busier Patch Tuesdays
FOE
CISA KEV
CVE-2026-48939: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
FRIEND
Sophos News
Sophos named a 2026 Gartner® Peer Insights™ Customers’ Choice for Email Security
FOE
CSO Online
AI coding tool hole illustrates a big problem with human in the loop
FOE
The Register (Security)
An unnamed US county – perhaps in Ohio – paid $1M extortion demand to cybercriminals
FOE
Bleeping Computer
OpenMandriva Linux says contributor tried to sabotage the project
FRIEND
Professor Messer
Professor Messer’s CompTIA A+ 220-1202 Study Group – July 2026
FOE
EFF Deeplinks
"We Want Texans to Know Their Rights": Q&A with Mayday Health on the Impact of Surveillance on Abortion Care
FOE
EFF Deeplinks
The House Passed The KIDS Act—The Senate Should Reject It
FOE
Ars Technica (Security)
Patch for Windows Defender 0-day could allow attackers to fill hard disk
FOE
Dark Reading
Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure
FRIEND
EPIC
EPIC Applauds the Massachusetts Senate for Passing Platform Design Regulations
FOE
Dark Reading
Microsoft Reins in RoguePlanet Zero-Day Threat
FOE
Bleeping Computer
Injective SDK on npm infected with cryptocurrency wallet stealer
FOE
Dark Reading
AI Agents Are a New Kind of Identity & Most Organizations Aren't Ready
FOE
The Hacker News
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
FOE
EFF Deeplinks
European Commission Chooses to Keep EU Users Locked Up Behind Big Tech’s Gates
FOE
The Hacker News
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
FOE
Bleeping Computer
New Helix vishing group emerges in SharePoint data theft attacks
FRIEND
Bleeping Computer
Microsoft expects more Windows security updates from AI-discovered flaws
FRIEND
The Hacker News
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
FOE
The Register (Security)
EU 'Chat Control' snoopfest returns after vote to kill it falls short
FOE
The Hacker News
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
FRIEND
SecurityWeek
QIZ Security Raises $17 Million for Cryptographic Governance Platform
FRIEND
Professor Messer
Today’s SY0-701 CompTIA Security+ Pop Quiz: Check the paperwork
FOE
Bleeping Computer
New Forg365 phishing platform uses AI to target Microsoft 365 accounts
FOE
Dark Reading
As Global Conflicts Go Digital, Businesses Need Wartime Gameplans
FRIEND
SecurityWeek
UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge
FOE
Bleeping Computer
The Hidden Security Risks of Reduced Summer IT Coverage
FOE
SecurityWeek
Palo Alto Networks Patches 13 Vulnerabilities
FOE
The Register (Security)
Microsoft closes book on Nightmare Eclipse's RoguePlanet zero-day
FOE
Dark Reading
AI Gateways Offer Attackers the Keys to the Kingdom
FOE
CSO Online
Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk
FOE
CSO Online
UK cyber agency unveils AI-powered Cyber Shield to counter attacks at machine speed
FOE
The Hacker News
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up
FOE
SecurityWeek
12 Million Impacted by Data Breach at Japanese Telco KDDI
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: I’d like a history question
FOE
CISA Alerts
OpenPLC v3
FOE
CISA Alerts
Schneider Electric Easergy MiCOM Px40 Series
FOE
CISA Alerts
Schneider Electric PowerChute Serial Shutdown
FOE
SecurityWeek
15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google
FOE
Schneier on Security
The Language of AI Could Change How Humans Speak
FOE
Bleeping Computer
Microsoft to retire the OWA Light client in Exchange Server
FRIEND
The Hacker News
Summer of Clearinghouses
FOE
The Hacker News
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
FOE
Privacy International
Humanless Resources? Uncovering AI recruitment software
FOE
SecurityWeek
Microsoft Patches Defender ‘RoguePlanet’ Vulnerability
FOE
SecurityWeek
Mount Royal University Confirms Data Stolen in Ransomware Attack
FOE
Dark Reading
'GodDamn' Ransomware Uses BYOVD to Smite US Companies
FOE
CSO Online
Agentic AI identity: A 6-stage maturity model for non-human identities
FOE
Bleeping Computer
Police arrests 5,800 suspects in global anti-fraud crackdown
FOE
EFF Deeplinks
Google's new remote attestation scheme is every bit as terrible as its old remote attestation scheme
FOE
CSO Online
Why fixing your data architecture matters more than upgrading your detection models
FOE
SecurityWeek
AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique
FOE
The Hacker News
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
FOE
Risky Business News
Srsly Risky Biz: Supreme Court Undermines Section 702
FOE
Dark Reading
European Organizations Have a Collaboration Security Confidence Gap
FOE
Bleeping Computer
AssuranceAmerica data breach exposes records of 6.9 million drivers
FOE
SecurityWeek
Chrome 150 Update Patches 27 Vulnerabilities
FOE
The Hacker News
Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images
FOE
The Register (Security)
Thief posed as Wi-Fi fixing hero, then stole priceless trophy
FOE
CSO Online
Lateral movement risk rises as enterprises emphasize convenience over containment
FRIEND
SecurityWeek
8Layers Raises $2.9 Million for Identity Security Platform
FOE
Bleeping Computer
Microsoft patches RoguePlanet Defender zero-day vulnerability
FOE
The Hacker News
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
FOE
SecurityWeek
Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices
FOE
The Hacker News
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
FOE
The Hacker News
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
FRIEND
SANS Internet Storm Center
_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th)
FOE
CSO Online
GitHub’s public APIs are becoming an enterprise reconnaissance tool
FOE
The Register (Security)
Suspected Chinese snoops caught breaking into universities' Roundcube mailservers
FOE
Dark Reading
Mexico's New Cyber Plan Faces Its First Real Test
FOE
Bleeping Computer
Mount Royal University confirms breach as hackers claim attack
FOE
Dark Reading
Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours
FOE
Bleeping Computer
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
FOE
The Register (Security)
GitHub Copilot: Sorry Dave, I can't do that harmful thing - unless you ask me in code
FOE
Ars Technica (Security)
Google pays $250k for Linux vulnerability allowing guest VM escapes
FOE
Bleeping Computer
Hackers exploit Roundcube flaw to spy on academic researchers
FOE
The Hacker News
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
FOE
Bleeping Computer
Entra passkey enrollment vishing targets Microsoft 365 users
FOE
Dark Reading
Vidar Infostealer Hammers SMBs via Malvertising Campaign
FOE
SecurityWeek
Accenture Confirms Data Breach After Hacker Claims Source Code Theft
FRIEND
BrightTALK InfoSec
How to Assess AI Security
FOE
SecurityWeek
China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors
FOE
The Hacker News
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware
FOE
The Hacker News
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
FOE
Bleeping Computer
3 Ways AI Powers Service Desk Attacks and How to Prevent Them
FOE
The Register (Security)
Bug in top AI coding agents shows that Unix-era security headaches never really die
FRIEND
Black Hills Information Security
Finding the “Goldilocks” Zone: A Practical Approach to Alert Triage
FOE
The Register (Security)
China tells devs to ditch Claude Code over 'backdoor code' fears
FRIEND
SecurityWeek
Webinar Today: Why Email Security Keeps Failing
FOE
The Hacker News
New Ghost Phishing Wave Is Breaking Traditional Email Security
FOE
The Hacker News
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
FOE
Krebs on Security
Felons, Fraudsters Flog Offensive Cybersecurity Startup
FOE
SecurityWeek
Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations
FOE
CSO Online
GitHub AI agent leaks private repositories via prompt injection attack
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: The sunset is over there
FRIEND
Bleeping Computer
DuckDuckGo browser now blocks YouTube video ads
FOE
CSO Online
Cybercriminals exploit India’s tax filing season with a dual-malware campaign
FOE
The Hacker News
GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
FOE
The Hacker News
The Verification Step Is the New ATO Battleground in 2026
FOE
Bleeping Computer
Telco giant KDDI says data breach affects over 12 million people
FOE
The Hacker News
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code
FOE
Schneier on Security
Cybersecurity and the Gap Between Skill and Ability
FOE
SecurityWeek
CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
FOE
SecurityWeek
Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection
FOE
Bleeping Computer
CISA orders feds to prioritize patching Langflow auth bypass flaw
FOE
The Hacker News
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
FOE
CSO Online
My threat feed told me it was ‘Chalubo.’ The binary disagreed
FOE
Bleeping Computer
Ubiquiti warns of new max severity UniFi OS vulnerability
FOE
SANS Internet Storm Center
My Stack Simulator, (Wed, Jul 8th)
FOE
Dark Reading
State IDs for AI Agents: Will Estonia Set a Precedent?
FOE
Bleeping Computer
CISA orders feds to patch max severity ColdFusion flaw by Friday
FOE
Ars Technica (Security)
Hackers can use 9 of the most popular AI tools to assemble massive botnets
FRIEND
CSO Online
13 in-demand IT security certifications for higher pay
FOE
The Hacker News
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
FOE
Risky Business News
Risky Bulletin: All new cars to include a camera aimed at the driver's face
FOE
The Hacker News
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
FOE
Bleeping Computer
Accenture confirms breach after hacker offers stolen data for sale
FOE
CSO Online
16-year-old KVM flaw allows attackers to escape VMs and take over Linux servers
FRIEND
Professor Messer
Professor Messer’s 220-1201 CompTIA A+ Study Group – July 2026
FOE
CSO Online
Watch out for fake support calls in Microsoft Teams
FOE
The Intercept (Privacy)
FBI Raided Texas Activist’s House — Then Offered Her $200,000 to Become Antifa Informant
FOE
Dark Reading
Big Brand Jobs Scam Targets Marketing Pros' Google Accounts
FOE
The Register (Security)
Windows is watching: Anti-piracy tool fingers Scattered Spider suspect
FOE
Dark Reading
Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft
FRIEND
BrightTALK InfoSec
Implement Data-Driven Security with AI and Visual Intelligence
FOE
The Register (Security)
GitHub AI agent leaks private repos when asked nicely
FOE
Bleeping Computer
Chinese hackers develop LONGLEASH malware to expand ORB network
FOE
SANS Internet Storm Center
More Odd DNS Records: NIMLOC, (Tue, Jul 7th)
FOE
SecurityWeek
County Government Reportedly Paid $1 Million to Cyber Extortion Group
FOE
Bleeping Computer
Hidden backdoor in Tenda router firmware grants admin access
FOE
SecurityWeek
Critical Gitea Flaw Under Active Exploitation, Researchers Warn
FOE
The Register (Security)
CAI cloud worm gives competitors' malware the boot, then steals secrets and mines for coin
FOE
The Hacker News
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
FOE
The Hacker News
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
FOE
EFF Deeplinks
Automated Moderation Is Here to Stay
FRIEND
EFF Deeplinks
Help EFF Cut the AI Hype
FOE
The Register (Security)
Predatorgate snoopfest victims launch €8M sueball at spyware maker
FOE
Dark Reading
'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows
FOE
Bleeping Computer
Spain arrests suspected member of pro-Russian hacktivist groups
FOE
The Hacker News
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
FRIEND
Professor Messer
Today’s N10-009 CompTIA Network+ Pop Quiz: Learn another language
FOE
The Hacker News
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
FOE
Bleeping Computer
The GitHub Actions Attack Pattern Your CI Security Scanners Miss
FOE
The Hacker News
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker
FOE
The Hacker News
Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants
FRIEND
SecurityWeek
CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws
FOE
The Register (Security)
Enterprise AI still smarting from leaping before looking
FOE
SecurityWeek
Critical Adobe ColdFusion Vulnerability Exploited in Attacks
FOE
SecurityWeek
Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks
FRIEND
Bleeping Computer
Webinar tomorrow: Why modern email attacks require a new approach to defense
FOE
Bleeping Computer
New Januscape Linux flaw allows VM escape on Intel, AMD devices
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: Bury it in the backyard
FOE
CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog
FOE
CISA Alerts
CISA Adds Three Known Exploited Vulnerabilities to Catalog
FOE
CISA Alerts
Hitachi Energy PROMOD V
FOE
CISA Alerts
Siemens Mendix Studio Pro
FOE
CISA Alerts
Hitachi Energy e-mesh EMS
FOE
CISA Alerts
Hydro-Québec Le Circuit Electrique charging station backend
FOE
CISA Alerts
Digi International PortServer TS, Digi One SP IA
FOE
CISA Alerts
Labcenter Proteus 9
FOE
CISA Alerts
Siemens SINEC OS
FRIEND
SecurityWeek
CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker
FOE
The Hacker News
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
FOE
The Register (Security)
Fake IT bods on Microsoft Teams coax workers into installing malware
FOE
Schneier on Security
Google Is Suing Chinese Scammers Who Are Using Gemini
FOE
The Register (Security)
Spain collars alleged pro-Russia hacktivist after FBI tip-off
FRIEND
The Register (Security)
Government's cyber pledge lands 60 signatories, including M&S and, somehow, Capita
FOE
SecurityWeek
Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems
FOE
CSO Online
Why The Gentlemen ransomware is a test of identity and recovery controls
FRIEND
Bleeping Computer
Microsoft to enable Windows settings backup by default for orgs
FRIEND
SecurityWeek
Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security
FOE
The Hacker News
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
FRIEND
CSO Online
The modern CISO is becoming the next CFO
FOE
Bleeping Computer
BeyondTrust warns of critical flaws in remote access software
FRIEND
Bleeping Computer
Microsoft testing new Cloud Rebuild Windows 11 recovery feature
FOE
The Hacker News
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
FOE
The Hacker News
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
FRIEND
CSO Online
Insignary Closes SBOM Accuracy Gap With Binary-Level Clarity for Regulatory Risk
FOE
CSO Online
AI agents fall for indirect prompt injection traps
FOE
CSO Online
Zscaler finds autonomous agents succumb to IPI traps
FOE
CISA KEV
CVE-2026-48282: Adobe ColdFusion Path Traversal Vulnerability
FOE
Sophos News
When AI agents look like attackers: what behavioral telemetry tells us
FOE
CISA KEV
CVE-2026-56290: Joomlack Page Builder Improper Access Control Vulnerability
FOE
CISA KEV
CVE-2026-55255: Langflow Authorization Bypass Through User-Controlled Key Vulnerability
FOE
CISA KEV
CVE-2026-48908: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
FOE
Dark Reading
'BusySnake' Infostealer Slithers into Critical Infrastructure Networks
FOE
Dark Reading
CitrixBleed-ing Again? NetScaler Vulnerability Under Attack
FOE
Bleeping Computer
Phishing poses as big-brand job interview to steal Google accounts
FOE
Bleeping Computer
Fake IT support calls on Microsoft Teams push EtherRAT malware
FOE
SecurityWeek
Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks
FOE
The Hacker News
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
FOE
The Hacker News
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
FOE
The Register (Security)
EU urged to act after Pegasus infects phone of spyware inquiry MEP
FOE
Dark Reading
JadePuffer: The First Complete LLM-Driven Ransomware Attack
FOE
The Hacker News
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
FRIEND
SecurityWeek
The Shift Toward Business-Aligned Risk Management
FOE
SecurityWeek
Armored Likho APT Targeting Government, Electric Power Entities
FOE
CSO Online
The agentic blind spots in your zero trust program
FOE
CSO Online
Identity: The operational control plane for agentic AI
FOE
CSO Online
Operationalizing Agentic AI: from assisted to autonomous
FRIEND
BrightTALK InfoSec
Proving Threat Hunting ROI: Outcome-Based KPIs for the Modern SOC
FOE
Bleeping Computer
Software Is Now Written at the Speed of Thought. Security Isn't.
FRIEND
SANS Internet Storm Center
RCS and DNS: The NAPTR Record, (Mon, Jul 6th)
FOE
Bleeping Computer
Max severity Adobe ColdFusion flaw now exploited in attacks
FOE
SecurityWeek
North Korean Hackers Target Open Source Developers in Supply Chain Attacks
FOE
The Hacker News
⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
FOE
SecurityWeek
Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability
FOE
The Register (Security)
Brit supermarket giant triples down on facial recog to nab shoplifters
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: Try using high test
FOE
CSO Online
This AI agent autonomously hacked a network, adapted on the fly, and demanded a ransom
FRIEND
The Hacker News
How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions
FOE
SecurityWeek
Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments
FOE
The Hacker News
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
FOE
The Register (Security)
Moody Bible Institute breach leaves 2.3M accounts needing salvation, says cyber expert
FOE
Schneier on Security
France to Stop Certifying Non-Quantum-Safe Encryption
FOE
CSO Online
Single points of failure fail. The SaaS layer is not an exception
FRIEND
The Register (Security)
Secure Unix ancestor KSOS did type safety before Rust made it cool
FOE
CSO Online
AI isn’t closing the skills gap — it’s exposing the validation gap
FOE
The Hacker News
New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions
FOE
The Hacker News
New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS
FOE
The Hacker News
Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages
FRIEND
OWASP Blog
OWASP CVE Lite CLI Graduates to Lab Project Status
FRIEND
CSO Online
7 cyber risk assessment gotchas to avoid
FOE
The Hacker News
SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing
FRIEND
Risky Business News
Risky Bulletin: Android drops PIN guessing limit from 1,800 attempts to just 20
FOE
Sophos News
"Exploit mitigation" stalled around 2008. The attacks didn't.
FOE
The Register (Security)
MFA-optional banks leave safe doors (and accounts) wide open for thieves to pillage
FRIEND
Bleeping Computer
Flipper Zero firmware development continues with community help
FOE
Bleeping Computer
JadePuffer ransomware used AI agent to automate entire attack
FOE
The Hacker News
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
FOE
The Hacker News
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
FOE
The Register (Security)
Confidential computing's trust mechanism is broken. The fix may not exist
FOE
The Register (Security)
Confidential computing's core trust mechanism is broken. The fix may not exist
FOE
The Hacker News
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
FOE
The Hacker News
New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
FOE
The Hacker News
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
FOE
Bleeping Computer
NetNut proxy network disrupted, 2 million infected devices cut off
FOE
The Hacker News
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
FOE
CSO Online
Microsoft 365 users fall victim to one-in-a-million password spray attack
FOE
SecurityWeek
In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting
FOE
The Register (Security)
AdaptHealth says attackers sweet-talked their way into cloud systems and stole patient data
FOE
Bleeping Computer
ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit
FRIEND
CSO Online
Adobe premieres a second Patch Tuesday each month to deliver fixes faster
FOE
The Hacker News
Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
FOE
Dark Reading
Chinese LLMs Broaden the Gap Between Attackers & Defenders
FOE
The Register (Security)
NetNut cracked as Google and FBI target 2 million-device botnet
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: It’s air tight
FOE
CSO Online
New CitrixBleed-like NetScaler flaw sees exploit attempts in the wild
FOE
Schneier on Security
Flock Cameras Can Surveil Cars Without License Plates
FOE
The Hacker News
European Parliament Member Investigating Spyware Was Hacked With Pegasus
FOE
SecurityWeek
Agentic AI Used to Conduct Ransomware Attack via Langflow
FOE
SecurityWeek
Medtronic Data Breach Impacts 3.8 Million People
FOE
SecurityWeek
Alleged Scattered Spider Hacker Extradited to US
FOE
SecurityWeek
Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices
FOE
The Hacker News
PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
FOE
SecurityWeek
Critical Cursor AI IDE Flaws Could Lead to OS-Level Remote Code Execution
FOE
The Register (Security)
User swore hacker called General Failure had invaded his PC
FOE
Risky Business News
Risky Bulletin: FatFs bugs enable physical access attacks on a load of devices
FOE
Bleeping Computer
Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says
FOE
Bleeping Computer
Claude Fable relaunch disappoints users with nerfed performance
FOE
The Register (Security)
Dev says Google warned him about account hijack – then charged him $11,000 anyway
FOE
Dark Reading
Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs
FOE
The Register (Security)
Startup sues Palo Alto Networks' Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage
FRIEND
BrightTALK InfoSec
Translate Security Operations Metrics into Business Risk Intelligence
FOE
Ars Technica (Security)
Newly discovered PamStealer isn't your typical macOS malware
FOE
Dark Reading
Apple Reverses Age-Old Patch Policy to Keep Up With AI
FOE
Krebs on Security
FBI Seizes NetNut Proxy Platform, Popa Botnet
FOE
Dark Reading
FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs
FOE
The Hacker News
Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices
FOE
The Hacker News
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
FOE
Dark Reading
Ransomware Thugs Masquerade as Interpol to Entice Small Biz
FOE
The Register (Security)
Smooth AI criminal drives 'first' end-to-end agentic ransomware attack
FRIEND
EPIC
New Jersey Bans the Sale of Sensitive Data, Creates Data Broker Registry
FOE
EFF Deeplinks
LGBT Q&A: How Can I Wipe Online Data That Points To My Queer Identity?
FOE
The Register (Security)
Ctrl+Alt+Oops: FortiBleed criminal's logins stitch two gangs together
FOE
The Hacker News
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories
FOE
Bleeping Computer
Google loses final appeal to overturn €4.1 billion EU fine
FOE
EFF Deeplinks
EFF and Allies: X’s FTC Petition to Waive Privacy Violation Order Should be Rejected
FOE
SecurityWeek
New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure
FRIEND
Professor Messer
Today’s SY0-701 CompTIA Security+ Pop Quiz: Sound it out
FOE
The Register (Security)
Microsoft said exploitation was 'less likely' ... but CISA just added SharePoint RCE to KEV list
FOE
Bleeping Computer
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
FRIEND
SecurityWeek
How to Conduct a Successful Audit of AI-Driven Software Development
FOE
The Hacker News
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
FOE
The Register (Security)
Pacemaker manufacturer Medtronic warns patients cybercrooks may have swiped health data
FOE
SecurityWeek
FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks
FRIEND
Dark Reading
Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.
FRIEND
Bleeping Computer
Microsoft fixes bug that removed Copilot buttons in Outlook
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: I can do that
FOE
CISA Alerts
CubeSpace CW0057 Reaction Wheel
FOE
CISA Alerts
ST Engineering iDirect iQ-Series Terminals
FOE
CISA Alerts
Gardyn IoT Hub
FOE
The Register (Security)
India gives WhatsApp three days to defend username rollout amid security fears
FOE
Bleeping Computer
Cisco finally confirms attackers exploiting Unified CM flaw
FOE
The Hacker News
Identity Lifecycle Management Wasn't Built for AI Agents
FOE
Schneier on Security
Cybersecurity Mission Creep in the US
FOE
SecurityWeek
Trump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity Alarm
FOE
CSO Online
Argo CD flaw shows why GitOps infrastructure should be treated as tier zero
FOE
Bleeping Computer
CISA: Microsoft SharePoint RCE flaw now actively exploited
FOE
SecurityWeek
Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability
FRIEND
Bleeping Computer
Opera rolls out Paste Protect feature to fight ClickFix attacks
FOE
SecurityWeek
‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials
FOE
The Register (Security)
Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released
FOE
SecurityWeek
CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability
FOE
The Hacker News
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
FOE
Bleeping Computer
Alleged Scattered Spider hacker extradited to the United States
FOE
The Hacker News
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
FOE
The Hacker News
New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
FOE
The Register (Security)
Hackers shoveled snow for company, were rewarded with network admin access
FOE
The Hacker News
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
FOE
Risky Business News
Srsly Risky Biz: America Won't Beat the Distillation Ecosystem
FOE
Bleeping Computer
Medtronic notifies customers impacted by ShinyHunters data breach
FOE
CSO Online
Sandbox bypass flaws in Cursor IDE highlight prompt injection as an RCE vector
FOE
Sophos News
Vect and TeamPCP partner for ransomware campaigns
FOE
The Register (Security)
EvilTokens device-code phishing kit totally more evil than we all thought
FOE
Bleeping Computer
FortiBleed credential-theft campaign linked to Lynx ransomware
FRIEND
The Register (Security)
Claude Sonnet 5.0 heads straight down the middle of the road to dodge controversy
FRIEND
EPIC
EPIC Commends California For Protecting User Privacy and Speech in Proposed Age Assurance Rules
FOE
Bleeping Computer
Kubota says hackers had month-long access to network systems
FOE
Dark Reading
Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS
FOE
Bleeping Computer
New ChocoPoC malware targets researchers via trojanized PoC exploits
FOE
The Register (Security)
Somebody told DeepSeek to build in-browser ransomware and it gleefully complied
FOE
Dark Reading
And the Winner in Dominant Malware Delivery? ClickFix
FOE
The Hacker News
Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters
FOE
The Hacker News
19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges
FRIEND
SecurityWeek
Microsoft Adds New Teams Controls to Block Unauthorized AI Bots From Meetings
FOE
The Hacker News
SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
FOE
Bleeping Computer
DHS confirms hackers breached HSIN info-sharing platform
FOE
The Hacker News
VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer
FOE
The Register (Security)
Red teamers turned Claude Desktop into a double agent to do their evil bidding
FRIEND
Bleeping Computer
Webinar: Why traditional email security is no longer enough
FOE
Bleeping Computer
Hackers target Microsoft 365 accounts with 81 million login attempts
FRIEND
EPIC
New Jersey Legislature Passes Grocery Surveillance Pricing Ban
FRIEND
Dark Reading
When Too Much Security Data Became the Risk
FOE
The Hacker News
Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures
FRIEND
The Hacker News
Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
FOE
Dark Reading
'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat
FOE
The Hacker News
Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
FRIEND
Bleeping Computer
Turning Indicators into Intelligence in OpenCTI with Criminal IP
FRIEND
BrightTALK InfoSec
Strengthening Supply Chain Resilience in a High-Risk Geopolitical Environment
FOE
Black Hills Information Security
Finding and Addressing Vulnerable and Outdated Web Application Components
FOE
The Hacker News
Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
FRIEND
Dark Reading
Safe Events Start With Threat Intel and Digital Security
FOE
The Hacker News
AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android
FOE
Bleeping Computer
Over 900 Oracle E-Business instances exposed to ongoing attacks
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: Get the wood glue ready
FOE
CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog
FOE
The Hacker News
2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience
FOE
SecurityWeek
Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities
FRIEND
SecurityWeek
Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack
FOE
Schneier on Security
Papa Johns Surveillance-Based Advertising
FRIEND
The Hacker News
Microsoft Accelerates Post-Quantum Cryptography Shift to 2029
FRIEND
SecurityWeek
Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors
FOE
Bleeping Computer
Amazon fined $2.25M for withholding evidence from fraud victims
FRIEND
SecurityWeek
Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari
FRIEND
SecurityWeek
Dawnguard Raises $6.3 Million for Security Architecture Automation Platform
FOE
SecurityWeek
Massive Password Spray Campaign Targeting Azure CLI
FRIEND
Bleeping Computer
Adobe patches seven max severity ColdFusion, Campaign flaws
FOE
The Hacker News
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
FOE
Risky Business News
Risky Bulletin: Researcher drops giant cache of zero-day exploits
FRIEND
CSO Online
Detection engineering: A programmatic approach to identifying cyber threats
FOE
The Hacker News
Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls
FOE
SecurityWeek
Google Patches 382 Chrome Vulnerabilities
FOE
The Hacker News
Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
FOE
The Hacker News
Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery
FOE
SANS Internet Storm Center
Why Ask Credentials If There Are Secret Codes?, (Wed, Jul 1st)
FOE
The Hacker News
Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
FOE
Dark Reading
China-Linked Group Targets Southeast Asia Critical Systems
FRIEND
EPIC
PRESS RELEASE: EPIC Applauds Passage of the New Jersey Kids Code Act
FRIEND
Bleeping Computer
Anthropic to restore Claude Fable access on Wednesday
FOE
CISA KEV
CVE-2026-45659: Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability