InfoSecRadar InfoSecRadar
  • Home
    • Vulnerabilities & Exploits
    • Malware & Ransomware
    • Data Breaches & Leaks
    • Threat Actors & Campaigns
    • Policy & Regulation
    • Industry & Career
    • Tools & Techniques
    • Cloud & Infrastructure
    • AI & Cybersecurity
    • Privacy & Surveillance
    • Signal School
  • Friend
  • Foe
  • Archive
  • About

Archive: July 2026

1402 stories.

← August 2026 All months June 2026 →
FOE Jul 31 Bleeping Computer
Amgen says cloud data breach exposed patient health, proprietary info
FOE Jul 31 Bleeping Computer
Arch Linux disables AUR package adoption to stop malware flood
FOE Jul 31 Bleeping Computer
Online ad firm Adform’s script compromised to steal cryptocurrency
FOE Jul 31 Ars Technica (Security)
Claude published malicious code to the Internet and attacked 3 real companies
FOE Jul 31 EFF Deeplinks
Amending AB 1709 Doesn’t Fix It: California’s Social Media Ban Still Threatens Free Speech and Privacy
FOE Jul 31 EFF Deeplinks
The SCREEN Act Threatens Privacy Far Beyond Adult Websites
FRIEND Jul 31 EPIC
Illinois Governor Signs Age-Appropriate Design Code into Law
FOE Jul 31 EPIC
EPIC Urges FTC to Abandon Misleading Guidance Suggesting Consumer Protection Laws Preempt State AI Regulations
FOE Jul 31 EFF Deeplinks
The CHATBOT Act Forces One Parenting Model On Every Family
FOE Jul 31 Bleeping Computer
OpenAI says its new GPT 5.6 models are becoming more cost-efficient
FOE Jul 31 The Hacker News
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
FRIEND Jul 31 Dark Reading
CISA Issues Fresh SBOM Guidance. Did They Get It Right?
FOE Jul 31 Bleeping Computer
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
FRIEND Jul 31 Schneier on Security
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
FOE Jul 31 Bleeping Computer
CISA warns of cyberattacks disrupting U.S. water utilities
FOE Jul 31 The Hacker News
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
FOE Jul 31 The Register (Security)
The most famous brand in physical security got pwned by ShinyHunters
FOE Jul 31 CSO Online
DefCon security conference bans smart glasses with recording capabilities
FOE Jul 31 SecurityWeek
In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
FOE Jul 31 SecurityWeek
Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers
FOE Jul 31 The Register (Security)
Anthropic and OpenAI are competing to see whose agents can go rogue harder
FOE Jul 31 The Hacker News
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
FOE Jul 31 Ars Technica (Security)
AI scammers outperform humans when it comes to building trust
FOE Jul 31 Bleeping Computer
ESET tracks rise in malicious AI skills and adaptable malware
FOE Jul 31 BrightTALK InfoSec
Automating Evidence and Policy Checks for AIOps
FRIEND Jul 31 Dark Reading
The Morning After We Pull a Root of Trust, Nobody Owns It
FOE Jul 31 The Register (Security)
Charities remain locked out of CAF Bank online accounts
FOE Jul 31 CSO Online
Google adds to confusion with new names for threat actors
FOE Jul 31 CSO Online
Broadcom patches vulnerabilities all over VMware
FOE Jul 31 Dark Reading
Interpol Leverages Global System to Curtail Fraud Payments
FRIEND Jul 31 Dark Reading
DROP Platform Lets Californians Reduce Digital Footprint
FOE Jul 31 CSO Online
Microsoft almost gave away the keys to everyone’s Azure Cosmos DBs
FOE Jul 31 The Hacker News
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
FRIEND Jul 31 Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: Thin and wispy
FOE Jul 31 The Hacker News
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
FRIEND Jul 31 Pen Test Partners
If you’re going to vibe code it, why not vibe pen test it?
FOE Jul 31 The Hacker News
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
FOE Jul 31 The Hacker News
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
FOE Jul 31 Schneier on Security
Facial Recognition at Madison Square Garden
FOE Jul 31 CSO Online
JetBrains says a crafted HTTP request could break TeamCity
FOE Jul 31 SecurityWeek
Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace
FOE Jul 31 SecurityWeek
EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels
FOE Jul 31 SecurityWeek
Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations
FRIEND Jul 31 SANS Internet Storm Center
zipdump.py: Metadata Encoding, (Fri, Jul 31st)
FOE Jul 31 SecurityWeek
Critical Flaw Led to Azure Cosmos DB Pwnage
FOE Jul 31 CSO Online
After OpenAI, Anthropic finds Claude breached three organizations during cyber tests
FRIEND Jul 31 CSO Online
5 key priorities for your Black Hat agenda — and what to avoid
FOE Jul 31 SecurityWeek
CareCloud Data Breach Impacts Over 350,000
FOE Jul 31 SecurityWeek
Critical Code Execution Vulnerability Patched in TeamCity
FOE Jul 31 The Hacker News
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
FOE Jul 31 Risky Business News
Risky Bulletin: Non-profit offers $22,000 bounty for INC ransomware group
FOE Jul 31 The Register (Security)
Anthropic’s Claude escaped test sandbox to attack three organizations
FOE Jul 31 CSO Online
Copilot worm can spread through Microsoft Word docs
FOE Jul 31 CSO Online
Microsoft confirms an AI worm is propagating through Copilot and other MS apps
FOE Jul 31 Bleeping Computer
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
FOE Jul 31 Sophos News
When AI doesn’t know the target is real
FRIEND Jul 31 Sophos News
Three-headed dogs and long tails: Sophos at BSides LV
FOE Jul 30 Bleeping Computer
South Korea fines telco giant KT $39 million for customer data breach
FOE Jul 30 SecurityWeek
CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
FOE Jul 30 Bleeping Computer
JetBrains warns of critical TeamCity remote code execution flaw
FOE Jul 30 CSO Online
A coordinated attack hit 30+ Minnesota water systems. Who did it, and what does a Rockwell notice add to the picture?
FOE Jul 30 Dark Reading
Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
FRIEND Jul 30 SecurityWeek
Bank of America to Acquire Cybersecurity Firm MDSec
FOE Jul 30 Ars Technica (Security)
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
FOE Jul 30 Dark Reading
AI Harnesses Burst With Potential Exploit Opps
FRIEND Jul 30 SecurityWeek
Okta to Acquire Identity Threat Detection Firm Permiso
FOE Jul 30 The Hacker News
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
FOE Jul 30 Bleeping Computer
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
FOE Jul 30 Bleeping Computer
VMware fixes three critical flaws allowing auth bypass, VM escapes
FRIEND Jul 30 Bleeping Computer
Google says AI helped Chrome fix 1,072 security bugs in two releases
FOE Jul 30 Krebs on Security
Read This Before You Buy That TV Streaming Stick
FOE Jul 30 Bleeping Computer
ShinyHunters claims Brinks Home breach, threatens to leak stolen data
FOE Jul 30 Schneier on Security
American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials
FOE Jul 30 Bleeping Computer
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
FRIEND Jul 30 SecurityWeek
Timeless Compliance: Why Better Questions Beat Bigger Frameworks
FOE Jul 30 Dark Reading
Claude Mythos — Hype vs. Reality: What Security Teams Need to Know
FOE Jul 30 The Hacker News
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
FOE Jul 30 Bleeping Computer
Analog Devices discloses data breach, says operations unaffected
FRIEND Jul 30 Professor Messer
Today’s SY0-701 CompTIA Security+ Pop Quiz: I didn’t see you there
FOE Jul 30 EPIC
PRESS RELEASE: Challenge to DOGE’s Unlawful Seizure of Payment System Data Advances
FOE Jul 30 Bleeping Computer
After the Break-In: What Attackers Do Once They're Already Inside
FRIEND Jul 30 SecurityWeek
DataBahn Raises $40 Million for Agentic Data Pipeline Management
FOE Jul 30 The Hacker News
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
FRIEND Jul 30 SecurityWeek
Discern Security Raises $13 Million in Series A Funding
FRIEND Jul 30 SecurityWeek
Cantina Emerges From Stealth With $8 Million in Funding
FOE Jul 30 CSO Online
AI agents gain access to financial workflows amid growing governance gaps
FOE Jul 30 CSO Online
Critical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridge
FRIEND Jul 30 SecurityWeek
Onyx Security Raises $113 Million to Control AI Agents in the Enterprise
FOE Jul 30 SecurityWeek
‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale
FRIEND Jul 30 Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: I brought treats
FOE Jul 30 CISA Alerts
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
FOE Jul 30 CISA Alerts
MikroTik RouterOS
FOE Jul 30 CISA Alerts
NASA Core Flight System (cFS) Health & Safety (HS) Application
FOE Jul 30 CISA Alerts
Watchfire Controller Software
FOE Jul 30 CISA Alerts
Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
FOE Jul 30 CISA Alerts
MZ Automation lib60870
FOE Jul 30 CISA Alerts
Toptech Systems RCU II+ and Multiload II+
FOE Jul 30 CISA Alerts
Schneider Electric IGSS
FOE Jul 30 CISA Alerts
Johnson Controls OpenBlue Employee
FOE Jul 30 CISA Alerts
MZ Automation GmbH libiec61850
FOE Jul 30 CISA Alerts
o6 Automation open62541
FOE Jul 30 CISA Alerts
Mitsubishi Electric CC-Link IE TSN Communication Protocol
FRIEND Jul 30 CISA Alerts
Open Source Software: Security Principles and Practices
FOE Jul 30 The Hacker News
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
FRIEND Jul 30 The Hacker News
The Network Has Become the Control Plane for AI Security
FOE Jul 30 SecurityWeek
Semiconductor Firm Analog Devices Discloses Data Breach
FOE Jul 30 Schneier on Security
Should You Use AI for a Task? Here’s a Simple Way to Decide
FOE Jul 30 CSO Online
Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover
FOE Jul 30 The Hacker News
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
FOE Jul 30 The Hacker News
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
FOE Jul 30 The Register (Security)
Russian spies take their half-click email attack from Zimbra to Outlook
FOE Jul 30 SecurityWeek
Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms
FOE Jul 30 SecurityWeek
1 in 5 Data Center Assets Are Within Easy Reach of Attackers
FOE Jul 30 CSO Online
A Scattered Spider member was indicted. Microsoft’s GDID went to trial.
FRIEND Jul 30 SecurityWeek
US and Allies Update SBOM Guidance
FRIEND Jul 30 SecurityWeek
Chrome 151 Patches 370 Vulnerabilities
FOE Jul 30 The Hacker News
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
FOE Jul 30 The Hacker News
FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
FOE Jul 30 Risky Business News
Srsly Risky Biz: Chipping Away at Chinese AI Risks
FOE Jul 30 The Register (Security)
Headteacher had the most guessable username-password combo you could imagine
FOE Jul 30 SecurityWeek
Cisco Secure FMC Zero-Day Exploited in the Wild
FOE Jul 30 The Register (Security)
Excuses like 'AI did it' don't exist in the eyes of the law
FOE Jul 30 The Hacker News
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
FOE Jul 30 The Hacker News
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
FOE Jul 30 Dark Reading
SE Asian Cybercriminal Syndicates Become a Global Power
FRIEND Jul 30 CSO Online
CISA unveils a six-step blueprint for isolating critical infrastructure during cyberattacks
FOE Jul 30 SANS Internet Storm Center
Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th)
FOE Jul 30 Dark Reading
'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China
FOE Jul 29 Bleeping Computer
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
FRIEND Jul 29 Dark Reading
Cybersecurity, Then & Now
FOE Jul 29 Ars Technica (Security)
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
FOE Jul 29 Bleeping Computer
Anthropic confirms Claude is down worldwide
FOE Jul 29 Bleeping Computer
Cisco warns of FMC static credential flaw exploited in zero-day attacks
FOE Jul 29 Dark Reading
OpenAI's Rogue Model Claims More Victims Beyond Hugging Face
FRIEND Jul 29 Dark Reading
Red Agents vs. Blue Agents: How to Make AI Better At Defense
FOE Jul 29 The Register (Security)
Closed models refuse to help researcher swat Linux bug
FOE Jul 29 The Hacker News
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
FOE Jul 29 Bleeping Computer
Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
FOE Jul 29 Dark Reading
Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions
FOE Jul 29 Dark Reading
Hugging Face Hack Lessons for Cyber Defenders
FOE Jul 29 Schneier on Security
Measuring the Tendency of AI Agents to Go Rogue
FOE Jul 29 Dark Reading
When AppSec Scanners Become a Supply Chain Attack Vector
FOE Jul 29 EFF Deeplinks
🏃 Fitness Tracker Privacy Fails | EFFector 38.14
FOE Jul 29 The Register (Security)
Word worm crawls into Copilot, spreads chaos
FOE Jul 29 Bleeping Computer
OpenAI agent used exposed credentials at 4 services in Hugging Face breach
FOE Jul 29 SpecterOps
Clustered Points of Failure
FOE Jul 29 Ars Technica (Security)
Anthropic is finding bugs faster than Microsoft can fix them
FOE Jul 29 The Hacker News
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
FOE Jul 29 The Hacker News
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
FOE Jul 29 CSO Online
Mythos takes its first shot at post-quantum cryptography
FRIEND Jul 29 CSO Online
Sweet Security Brings Autonomous Protection to the AI Enterprise with New Blocking Capabilities
FOE Jul 29 Bleeping Computer
Hackers target over 30 Minnesota water utilities in coordinated OT attack
FOE Jul 29 Dark Reading
Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms
FOE Jul 29 EPIC
The Christian Science Monitor: A US agency listed an AI immigration tool online. The disclosure vanished after our inquiry.
FOE Jul 29 Bleeping Computer
Your AI Agents Are Guessing at Scale: Permissions Decide the Damage
FRIEND Jul 29 Black Hills Information Security
Report As You Go: Maintaining Good Documentation for SOC Analysts
FRIEND Jul 29 Bleeping Computer
Windows 11 KB5101684 update released with 42 changes and fixes
FOE Jul 29 The Register (Security)
Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems
FOE Jul 29 The Hacker News
Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
FOE Jul 29 The Hacker News
Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
FOE Jul 29 SecurityWeek
US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security
FOE Jul 29 CSO Online
OpenAI rogue AI agent’s attack expanded beyond Hugging Face
FRIEND Jul 29 SecurityWeek
Mate Security Raises $35 Million for Agentic SOC
FRIEND Jul 29 SecurityWeek
ThreatLocker Raises $190 Million in Series F Funding
FOE Jul 29 The Hacker News
Mythos Asks the Right Question. It Doesn't Answer It.
FRIEND Jul 29 Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: I left them on the table
FOE Jul 29 CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog
FRIEND Jul 29 CISA Alerts
2026 Minimum Elements for a Software Bill of Materials (SBOM)
FOE Jul 29 The Hacker News
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
FOE Jul 29 SecurityWeek
Critical VM Escape Vulnerability Patched in VMware ESXi
FOE Jul 29 The Hacker News
73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
FOE Jul 29 Schneier on Security
Long-Lived Vulnerability in Microsoft Secure Boot
FOE Jul 29 The Hacker News
Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
FRIEND Jul 29 SecurityWeek
US, Australia Release OT Isolation Guidance for Critical Infrastructure
FOE Jul 29 SecurityWeek
OpenAI’s Rogue AI Ventured Beyond Hugging Face
FOE Jul 29 CSO Online
It’s easier to steal cargo than toothpaste
FRIEND Jul 29 SecurityWeek
Spur Raises $200 Million for IP Intelligence Platform
FOE Jul 29 CSO Online
Risk-based patching is the future. AI made it table stakes
FOE Jul 29 The Hacker News
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
FOE Jul 29 SecurityWeek
JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
FRIEND Jul 29 CSO Online
How MFA gets hacked — and strategies to prevent it
FOE Jul 29 SecurityWeek
Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
FOE Jul 29 The Hacker News
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
FRIEND Jul 29 SANS Internet Storm Center
Apple Patches Everything (July 2026), (Wed, Jul 29th)
FOE Jul 29 CSO Online
Ransomware report: VPNs in the crosshairs, AI attacks
FOE Jul 29 The Hacker News
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
FOE Jul 29 The Hacker News
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
FOE Jul 29 Risky Business News
Risky Bulletin: New Chinese cyber contractor identified
FOE Jul 29 SecurityWeek
ShinyHunters Claims Ernst & Young Hack
FOE Jul 29 The Hacker News
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
FOE Jul 29 The Register (Security)
America bans imported robots due to supply chain and security risks
FOE Jul 29 Schneier on Security
Measuring LLMs’ Ability to Perform Cryptanalysis
FRIEND Jul 29 CSO Online
Fortinet’s new FortiGate platform converges firewall, SASE technologies
FOE Jul 29 CSO Online
A 13-year-old flaw is exposing tens of thousands of data center management systems
FOE Jul 29 CSO Online
The CSO’s blind spot: Why platform engineering 2.0 is now a security imperative
FOE Jul 29 CSO Online
Arista patches maximum severity vulnerability that is already being exploited
FOE Jul 29 CISA KEV
CVE-2026-20316: Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
FRIEND Jul 29 Sophos News
Secure by Design in practice: a year of progress on Sophos Firewall
FOE Jul 28 The Register (Security)
JFrog's 0-days let OpenAI's models hack Hugging Face
FOE Jul 28 The Register (Security)
Looks like JFrog's 0-days let OpenAI's models hack Hugging Face
FOE Jul 28 EFF Deeplinks
San Francisco: Don’t Fall for Industry Defense of Surveillance Pricing
FOE Jul 28 Ars Technica (Security)
We now have a better understanding how OpenAI hacked into Hugging Face
FOE Jul 28 Dark Reading
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
FOE Jul 28 Bleeping Computer
CubePilot drone software dev hit by DNS hijacking to intercept traffic
FOE Jul 28 Dark Reading
Flaw From 2002 Exposes Data Centers to Server Takeover
FOE Jul 28 Bleeping Computer
OpenAI models used Artifactory zero-days to escape to the internet
FOE Jul 28 Dark Reading
When AI Agents Escape Sandboxes, Old Security Rules Apply
FRIEND Jul 28 Dark Reading
Stronger AI Safety Requires Peeking Inside the 'Black Box'
FRIEND Jul 28 The Register (Security)
Microsoft and Wiz mind-meld agents catch more than 90% of bugs
FOE Jul 28 The Hacker News
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
FRIEND Jul 28 Bleeping Computer
CISA shares advice on isolating vital systems during cyberattacks
FOE Jul 28 Bleeping Computer
vBulletin fixes critical pre-auth RCE flaw with public exploit
FOE Jul 28 Dark Reading
'Certighost' Flaw Haunts Microsoft Active Directory Certificates
FOE Jul 28 EFF Deeplinks
Why Are Gay Bars Building Databases of Their Patrons?
FRIEND Jul 28 The Register (Security)
DEF CON bans Meta-style 'pervert glasses'
FOE Jul 28 The Register (Security)
AI-found bugs aren't proving any easier to exploit despite the hype
FOE Jul 28 The Hacker News
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
FRIEND Jul 28 Professor Messer
Today’s N10-009 CompTIA Network+ Pop Quiz: I’ll take a number 4
FRIEND Jul 28 SecurityWeek
Cyera Acquiring Oasis Security in $1 Billion Deal
FOE Jul 28 The Hacker News
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
FOE Jul 28 EPIC
CNET: The Government’s Indictment of an Activist Tests Whether You Have a Right to Wipe Your Phone
FOE Jul 28 EPIC
BBC: How period trackers share your private details
FOE Jul 28 SecurityWeek
Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe
FOE Jul 28 Bleeping Computer
Is Your SSO Protected Against Modern Credential Attacks?
FOE Jul 28 The Register (Security)
Bank for charities pulls online services over security fears
FOE Jul 28 The Register (Security)
Charity bank pulls online services over third-party software flaw
FOE Jul 28 The Hacker News
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
FRIEND Jul 28 SecurityWeek
OT Security Startup Frenos Raises $1.52 Million
FRIEND Jul 28 CSO Online
Infoblox joins crowded EASM market with DNS-centric approach
FOE Jul 28 The Hacker News
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
FOE Jul 28 The Register (Security)
Uncle Sam needs you to fight for 6G leadership and security, lest Beijing get there first
FRIEND Jul 28 Dark Reading
Former Citigroup CISO Blauner on What Makes A Great Security Leader
FOE Jul 28 Bleeping Computer
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
FRIEND Jul 28 Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: We’re fresh out
FRIEND Jul 28 CISA Alerts
CI Fortify – Advice for isolating vital systems
FOE Jul 28 CISA Alerts
igloohome Smart Lock Mobile Application
FOE Jul 28 CISA Alerts
MikroTik RouterOS and Cloud Hosted Router
FOE Jul 28 CISA Alerts
Siemens Mendix Runtime
FOE Jul 28 CISA Alerts
Siemens SIMATIC S7-PLCSIM Advanced
FOE Jul 28 CISA Alerts
Siemens Desigo CC
FOE Jul 28 CISA Alerts
ABB KNX Update Tool
FOE Jul 28 CISA Alerts
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
FOE Jul 28 SpecterOps
Introducing Attack Path Management for Entra Agents in BloodHound Enterprise
FOE Jul 28 The Hacker News
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
FRIEND Jul 28 SpecterOps
Attack Path Management Comes to AWS
FRIEND Jul 28 SpecterOps
Designing an MCP Server for AI Agents: Why Wrapping Your API Is the Wrong Abstraction
FOE Jul 28 SpecterOps
Expanding attack path management to the AI frontier
FRIEND Jul 28 SecurityWeek
Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model
FOE Jul 28 Schneier on Security
Axon Is Another License Plate Surveillance Company
FOE Jul 28 SecurityWeek
Act Security Emerges from Stealth to Fight the Patch Problem
FRIEND Jul 28 SecurityWeek
Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker
FRIEND Jul 28 SecurityWeek
Hush Security Raises $30 Million for AI Agent Governance
FOE Jul 28 The Register (Security)
Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
FOE Jul 28 Bleeping Computer
Data breach at medical billing firm MCBS affects 1.26 million people
FOE Jul 28 CSO Online
Why your AI safety certificates are worthless at runtime
FRIEND Jul 28 SecurityWeek
Google Adopts New Threat Actor Naming System
FOE Jul 28 The Hacker News
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
FOE Jul 28 The Hacker News
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
FOE Jul 28 CSO Online
Hugging Face breach shows why incident response needs a multi-model AI strategy
FOE Jul 28 SANS Internet Storm Center
AutoIT Payload Injector , (Tue, Jul 28th)
FOE Jul 28 SecurityWeek
Unpatched Fastjson Vulnerability Exploited in Attacks
FOE Jul 28 SecurityWeek
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
FRIEND Jul 28 The Hacker News
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
FOE Jul 28 SecurityWeek
Origin Energy Data Breach Affects 900,000 Australians
FOE Jul 28 The Hacker News
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
FOE Jul 28 TrustedSec
AI Directives and AI Strategy Development
FOE Jul 28 CSO Online
Hackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accounts
FOE Jul 28 SecurityWeek
For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startup
FRIEND Jul 28 CSO Online
Microsoft unveils multi-model agentic cyber stack for security operations
FOE Jul 28 CSO Online
Samsung’s AI-powered glasses could be looking at your data
FOE Jul 28 CSO Online
Samsung’s entry into AI-powered glasses forces CISOs to again consider corporate risk
FOE Jul 28 Dark Reading
AI Agent Drives Espionage Attack on Thai Ministry of Finance
FOE Jul 28 Sophos News
Chaos in Teams vishing
FOE Jul 27 Bleeping Computer
Hackers target US firms in FastJson RCE zero-day attacks
FOE Jul 27 Bleeping Computer
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
FRIEND Jul 27 Ars Technica (Security)
Microsoft unveils AI security tools it says outperform competing platforms
FOE Jul 27 Dark Reading
Agentic Browsers Rewind Web Security by 20 years
FOE Jul 27 Bleeping Computer
New Dysphoria DDoS botnet spreads to 200k devices worldwide
FOE Jul 27 Bleeping Computer
New Certighost PoC exploit lets attackers hijack Windows domains
FOE Jul 27 Dark Reading
'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure
FOE Jul 27 EPIC
EPIC and CDT Urge FCC to Reconsider Invasive Know Your Customer Rulemaking Proposal
FOE Jul 27 Dark Reading
FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
FRIEND Jul 27 The Register (Security)
Microsoft's solution to AI security: more AI and more acronyms
FRIEND Jul 27 EFF Deeplinks
Missed EFF's Livestream with Adam Savage and iFixit? Listen Here!
FOE Jul 27 Dark Reading
Why Resetting Passwords No Longer Stops Attackers
FRIEND Jul 27 The Hacker News
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
FOE Jul 27 Dark Reading
Adversaries Don't Need a Zero-Day — They Read Your Rulebook
FOE Jul 27 Bleeping Computer
Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin
FOE Jul 27 The Hacker News
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
FOE Jul 27 The Register (Security)
Tech giants link hands to praise open AI models after OpenAI - Hugging Face attack
FOE Jul 27 BrightTALK InfoSec
Securing AI Agent Reasoning Against Logic-Layer Attacks in 90 Days
FOE Jul 27 Ars Technica (Security)
Activist charged with felony after giving border agent "duress code" that wiped his phone
FOE Jul 27 Bleeping Computer
Coca-Cola confirms data theft in Fairlife ransomware attack
FOE Jul 27 Bleeping Computer
Ernst & Young data breach claimed by ShinyHunters extortion gang
FOE Jul 27 The Hacker News
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
FRIEND Jul 27 SecurityWeek
New GitHub, PyPI Policies Boost Supply Chain Security
FOE Jul 27 The Hacker News
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
FOE Jul 27 Bleeping Computer
Shadow AI agents are multiplying. Here's how to find and secure them.
FOE Jul 27 The Register (Security)
Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update
FOE Jul 27 SecurityWeek
PTC Windchill Vulnerability Exploited in Ransomware Campaign
FOE Jul 27 The Hacker News
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
FOE Jul 27 SecurityWeek
MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection
FOE Jul 27 The Hacker News
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
FRIEND Jul 27 SecurityWeek
Nvidia and Tech Giants Launch AI Security Alliance
FRIEND Jul 27 Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: It sounds super
FOE Jul 27 CISA Alerts
CISA Adds Two Known Exploited Vulnerabilities to Catalog
FOE Jul 27 CSO Online
Certighost haunts Microsoft Active Directory Certificate Services
FOE Jul 27 SecurityWeek
Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack
FRIEND Jul 27 CSO Online
OpenAI not part of the new Open Secure AI Alliance
FRIEND Jul 27 SecurityWeek
Beelzebub Raises $3.4 Million for Hacker-Trapping Platform
FOE Jul 27 Schneier on Security
Cognyte Sells a Mobile Cell Surveillance Van
FRIEND Jul 27 SecurityWeek
What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out
FOE Jul 27 The Hacker News
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
FOE Jul 27 SecurityWeek
Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials
FOE Jul 27 SANS Internet Storm Center
Java Spring Boot "heapdump" scans, (Mon, Jul 27th)
FRIEND Jul 27 SecurityWeek
Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits
FOE Jul 27 CSO Online
The containment paradox: Why your ransomware playbook has the wrong people in charge
FOE Jul 27 SecurityWeek
DentaQuest Data Breach Potentially Impacts Over 23 Million People
FOE Jul 27 CSO Online
When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk
FOE Jul 27 The Hacker News
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
FRIEND Jul 27 The Hacker News
GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
FRIEND Jul 27 The Register (Security)
Google goes it alone with a new cybercrime crew taxonomy
FRIEND Jul 27 CSO Online
How CISOs can rise to the business resilience challenge
FOE Jul 27 Risky Business News
Risky Bulletin: A JSON RCE bug is about to rock the Java world
FOE Jul 27 SecurityWeek
MCBS Data Breach Affects 1.2 Million Individuals
FRIEND Jul 27 Sophos News
Why Sophos Has Become Its Own AI Test Lab
FRIEND Jul 27 Sophos News
Turn cybersecurity into a high-value business function with Sophos CISO Advantage
FOE Jul 27 CISA KEV
CVE-2026-16812: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
FOE Jul 27 CISA KEV
CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
FRIEND Jul 27 Sophos News
Introducing Sophos AI Defense
FOE Jul 26 SANS Internet Storm Center
Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)
FRIEND Jul 26 Bleeping Computer
GitHub, PyPI add time-absed defenses against supply chain attacks
FOE Jul 25 Bleeping Computer
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
FOE Jul 25 The Hacker News
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
FOE Jul 25 Bleeping Computer
Malicious sites use JavaScript to build malware in browser memory
FOE Jul 25 Bleeping Computer
ShinyHunters data leaks fuel $2,000 sextortion email scam
FOE Jul 25 The Hacker News
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
FOE Jul 25 The Hacker News
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
FOE Jul 25 The Hacker News
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
FOE Jul 25 The Hacker News
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
FOE Jul 25 Bleeping Computer
OpenAI confirms ChatGPT is down worldwide
FOE Jul 25 The Hacker News
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
FOE Jul 25 SecurityWeek
Rockwell Patches Code Execution Flaws in Arena Simulation Software
FOE Jul 24 The Register (Security)
Pope's official prayer app commits cardinal sin, leaks 700K+ users' info
FRIEND Jul 24 Dark Reading
CISOs vs. Boards: Myth or Misunderstanding?
FOE Jul 24 The Register (Security)
Europol flags 4,340 'horrific' URLs linked to The Com
FOE Jul 24 Bleeping Computer
OnTrac notifies customers of data breach after network hack
FOE Jul 24 Dark Reading
Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
FOE Jul 24 Bleeping Computer
Hermes AI agent used to automate attack on Thai Finance Ministry
FOE Jul 24 EPIC
PRESS RELEASE: Privacy Rights Advocates Challenge Trump-Vance Administration’s Secret Tracking of People Exercising their First Amendment Rights
FOE Jul 24 Bleeping Computer
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
FOE Jul 24 Bleeping Computer
Microsoft blames massive Microsoft 365 outage on maintenance bug
FOE Jul 24 The Hacker News
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
FOE Jul 24 SecurityWeek
In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
FOE Jul 24 The Hacker News
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
FOE Jul 24 Bleeping Computer
Chick-fil-A data breach affects more than 13,000 customers
FOE Jul 24 Bleeping Computer
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
FOE Jul 24 Dark Reading
Vatican's Official Prayer App Leaks 700K+ Global Users' PII
FOE Jul 24 Bleeping Computer
Europol flags 4,340 URLs for removal in 'The Com' crackdown
FOE Jul 24 Dark Reading
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
FOE Jul 24 The Register (Security)
Uncle Sam tells overseas cybercrooks their visas are canceled
FRIEND Jul 24 SecurityWeek
AegisAI Raises $36 Million for AI-Powered Email Security
FRIEND Jul 24 Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: There’s a bit of an echo
FOE Jul 24 The Hacker News
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
FOE Jul 24 The Hacker News
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
FOE Jul 24 The Hacker News
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
FOE Jul 24 SecurityWeek
Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday
FOE Jul 24 Bleeping Computer
Man gets six years for hacking 750 women's Snapchat accounts
FRIEND Jul 24 Schneier on Security
Why AI Needs a “Genie Coefficient”
FOE Jul 24 CSO Online
Top AIs invent same fake PyPl and npm package names
FOE Jul 24 CSO Online
Tycoon2FA takedown reshapes the phishing landscape
FOE Jul 24 The Hacker News
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
FOE Jul 24 The Hacker News
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
FOE Jul 24 The Hacker News
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
FOE Jul 24 Bleeping Computer
Clop ransomware targets Windchill, FlexPLM in data theft attacks
FOE Jul 24 Dark Reading
Europe's Multilingual Reality Exposes AI Security Gaps
FOE Jul 24 CSO Online
Ransomware groups are hammering your vulnerable VPNs
FOE Jul 24 The Hacker News
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
FOE Jul 24 The Hacker News
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
FOE Jul 24 SecurityWeek
Data Breach Confirmed After Australian Energy Giant Origin Is Hacked
FRIEND Jul 24 TrustedSec
CCPA Update: Cybersecurity Requirements (Part 2)
FOE Jul 24 Risky Business News
Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers
FOE Jul 24 CSO Online
AgentForger proves AI agents can become persistent insider threats
FOE Jul 23 The Register (Security)
OpenAI-Hugging Face attack doesn't mean agents are evil – unless you tell them to be
FOE Jul 23 The Register (Security)
Researchers replace downloaded macOS apps with evil twins, Apple shrugs
FOE Jul 23 EFF Deeplinks
Hundreds of Drone-as-First-Responder Programs Could Soon Be Launched Across the Country
FOE Jul 23 Dark Reading
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
FOE Jul 23 Bleeping Computer
New Dolphin X malware uses AI to rank high-value targets
FOE Jul 23 CSO Online
Check Point hole grants unauthenticated attackers full SmartConsole admin privileges
FOE Jul 23 Bleeping Computer
Australian energy provider Origin says data breach exposes client data
FOE Jul 23 Bleeping Computer
Fake Claude app promoted by Bing ads pushes SectopRAT malware
FOE Jul 23 CSO Online
4 ways AI-driven defense is rewriting the cybersecurity playbook
FOE Jul 23 The Intercept (Privacy)
Trump’s Crypto Corruption Puts Centrist Democrats in Bind
FOE Jul 23 The Hacker News
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
FOE Jul 23 Bleeping Computer
Russian hackers exploit Zimbra zero-click flaw for email theft
FOE Jul 23 The Register (Security)
Year-long Russian attacks infect users as soon as they look at an email
FOE Jul 23 Bleeping Computer
Hackers abuse Notepad++ plugins to stealthily install malware
FOE Jul 23 The Register (Security)
Millions of California-bought cars can be hijacked via Bluetooth
FOE Jul 23 CSO Online
Linux XFS has a decade-old race condition allowing full root access
FOE Jul 23 Bleeping Computer
Microsoft 365 outage affects Teams, SharePoint and other services
FOE Jul 23 The Register (Security)
Oracle drops 1,449 security patches like it's the new normal
FOE Jul 23 SecurityWeek
OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider
FOE Jul 23 The Hacker News
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
FRIEND Jul 23 Professor Messer
Today’s SY0-701 CompTIA Security+ Pop Quiz: Lemonade to go
FOE Jul 23 SecurityWeek
Is Patching Dead? Vulnerability Management in the Post-Mythos Era
FOE Jul 23 SecurityWeek
Chick-fil-A Accounts Get Fried in Credential Stuffing Attack
FOE Jul 23 The Register (Security)
Iran-linked crews are probing more flavors of US industrial kit
FRIEND Jul 23 Bleeping Computer
FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires
FRIEND Jul 23 SecurityWeek
Abstract Raises $25 Million to Expand Composable Security Operations Platform
FOE Jul 23 SANS Internet Storm Center
When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)
FOE Jul 23 The Hacker News
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
FOE Jul 23 The Hacker News
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
FOE Jul 23 The Register (Security)
One ChatGPT link could smuggle a rogue AI agent into your company
FOE Jul 23 SecurityWeek
Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models
FOE Jul 23 Bleeping Computer
EU fines Google $1 billion for search, app store antitrust violations
FRIEND Jul 23 The Register (Security)
If you get knocked on the head and get all your devices stolen and have amnesia, Google will let you back in with a selfie
FOE Jul 23 The Hacker News
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
FRIEND Jul 23 Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: I’ll get the hammer
FOE Jul 23 CISA Alerts
MZ Automation lib60870
FOE Jul 23 CISA Alerts
Johnson Controls XAAP Android
FOE Jul 23 CISA Alerts
MZ Automation libIEC61850
FOE Jul 23 CISA Alerts
Weintek cMT3092X
FOE Jul 23 CISA Alerts
Panduit IntraVUE
FOE Jul 23 CISA Alerts
Johnson Controls C-CURE 9000 and Victor application server
FOE Jul 23 CISA Alerts
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
FOE Jul 23 The Register (Security)
Swiss train maker tells ransomware crooks to get off at the next stop
FOE Jul 23 The Hacker News
How Synthetic Identity Fraud is Coming for Machine Identities
FOE Jul 23 Bleeping Computer
New RefluXFS Linux flaw lets attackers gain root privileges
FOE Jul 23 The Hacker News
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
FOE Jul 23 Dark Reading
Agentic AI Challenges Progress in Confidential Computing
FOE Jul 23 Schneier on Security
End-to-End Encryption and “Going Dark”
FOE Jul 23 SecurityWeek
Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses
FRIEND Jul 23 The Hacker News
Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
FOE Jul 23 Bleeping Computer
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
FRIEND Jul 23 SecurityWeek
Assaf Keren Appointed New CISO of Meta
FOE Jul 23 Bleeping Computer
Microsoft working to fix Exchange Online mailbox quarantine issue
FOE Jul 23 SecurityWeek
New Check Point Zero-Day Vulnerability Exploited in the Wild
FOE Jul 23 Bleeping Computer
Check Point warns of SmartConsole zero-day exploited in attacks
FOE Jul 23 The Hacker News
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
FOE Jul 23 Risky Business News
Srsly Risky Biz: Knives Are Out For Open-Weight AI Models
FOE Jul 23 The Register (Security)
Talking smack about a doctor got him access to private medical files
FOE Jul 23 Dark Reading
Brazilian Banking Trojan Actively Spreading in Portugal
FOE Jul 23 CSO Online
Microsoft’s 3-day patching directive comes with added operational risk
FOE Jul 23 The Hacker News
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
FOE Jul 23 SecurityWeek
US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices
FOE Jul 23 Dark Reading
Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain
FOE Jul 23 Sophos News
When the "attacker" is an AI agent
FOE Jul 22 Dark Reading
Flaws in Passkey Implementation Show Old Attacks Still Work
FOE Jul 22 CSO Online
German law enforcement claims to have ‘dismantled’ mega phishing-as-a-service group Kratos
FOE Jul 22 The Register (Security)
OpenAI scored an own goal with Hugging Face attack, showing how open Chinese models are winning
FOE Jul 22 The Register (Security)
OpenAI scored an own goal with HuggingFace attack, showing how open Chinese models are winning
FOE Jul 22 EFF Deeplinks
The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required
FRIEND Jul 22 Professor Messer
Professor Messer’s SY0-701 Security+ Study Group – July 2026
FOE Jul 22 Bleeping Computer
Upbound says hack caused $13 million in fraudulent Acima leases
FOE Jul 22 Dark Reading
Attackers Are Learning to Live Off the AI Toolchain
FOE Jul 22 CSO Online
Critical Zimbra security update fixes 9 vulnerabilities
FOE Jul 22 Bleeping Computer
South Korea discloses data breach impacting diplomats worldwide
FOE Jul 22 Dark Reading
Fake Bahrain Alert App Deploys Android Surveillance Malware
FOE Jul 22 The Hacker News
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
FOE Jul 22 CSO Online
Oracle’s July update fixes ten 10.0 vulnerabilities in Fusion Middleware
FOE Jul 22 The Hacker News
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
FOE Jul 22 SANS Internet Storm Center
Rondo Meets Geoserver, (Wed, Jul 22nd)
FOE Jul 22 Bleeping Computer
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
FOE Jul 22 The Register (Security)
Linux kernel team publishes 432 CVEs in two days
FOE Jul 22 Ars Technica (Security)
OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face
FRIEND Jul 22 CSO Online
Cisco’s new AI model tells code reviewers where to look for vulnerabilities
FOE Jul 22 Dark Reading
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
FOE Jul 22 Bleeping Computer
How enterprise GenAI can amplify ransomware risk — and how to contain it
FOE Jul 22 SecurityWeek
Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts
FOE Jul 22 The Hacker News
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
FRIEND Jul 22 SecurityWeek
Palo Alto Networks to Acquire Observability Platform Provider Embrace
FOE Jul 22 SecurityWeek
Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft
FRIEND Jul 22 Bleeping Computer
New InfraTrust report reveals infrastructure flaws admins should patch first
FRIEND Jul 22 TCM Security Blog
TCM Academy Course Release: Windows Evidence Acquisition and Triage
FRIEND Jul 22 Black Hills Information Security
The Life of a SOC Analyst: Responsibilities, Challenges, and Strategies for Success
FOE Jul 22 SecurityWeek
When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover
FOE Jul 22 CSO Online
OpenAI model escape puts enterprise AI defenses on notice
FOE Jul 22 Bleeping Computer
Adobe Chrome extension flaw let sites access private WhatsApp chats
FOE Jul 22 The Register (Security)
Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits
FRIEND Jul 22 SecurityWeek
StrongestLayer Raises $4.1 Million in Seed Funding Extension
FOE Jul 22 SecurityWeek
Vibe-Coded Apps Riddled With Exploitable Security Flaws
FOE Jul 22 The Hacker News
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
FRIEND Jul 22 Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: How quaint
FOE Jul 22 CISA Alerts
CISA Adds Two Known Exploited Vulnerabilities to Catalog
FRIEND Jul 22 The Hacker News
The Fastest Path to AI Adoption Runs Through Security
FOE Jul 22 The Register (Security)
Greedy ransomware crews return for seconds after victims cough up first extortion payments
FOE Jul 22 Bleeping Computer
CISA orders urgent action on actively exploited Langflow RCE flaw
FOE Jul 22 Dark Reading
EU Financial Institutions Leak Data Through Cookie Trackers
FOE Jul 22 SecurityWeek
Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks
FOE Jul 22 The Hacker News
Why Modern SOCs Need Multi-Layered Detections
FOE Jul 22 Schneier on Security
First-Person Identity Theft Story
FOE Jul 22 Bleeping Computer
Microsoft to stop Exchange 2016 / 2019 security updates in October
FRIEND Jul 22 SecurityWeek
Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation
FRIEND Jul 22 SecurityWeek
Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
FOE Jul 22 CSO Online
AI, security operations and the new race against time
FOE Jul 22 EFF Deeplinks
New EU Court of Justice Ruling on Platform Liability Could Cause Collateral Damage to Freedom of Expression
FOE Jul 22 SecurityWeek
Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife
FOE Jul 22 The Register (Security)
Council worker spared prison after four-day data-snooping spree
FOE Jul 22 SecurityWeek
OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face
FRIEND Jul 22 CSO Online
10 survival tips for CSOs who report to the CEO
FOE Jul 22 Bleeping Computer
Chick-fil-A discloses data breach after credential stuffing attacks
FOE Jul 22 The Hacker News
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
FOE Jul 22 Risky Business News
Risky Bulletin: Linux kernel discloses 442 CVEs as AI bugpocalypse settles in
FOE Jul 22 The Hacker News
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
FOE Jul 22 Bleeping Computer
OpenAI says its AI models hacked Hugging Face during testing
FOE Jul 22 The Hacker News
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
FOE Jul 22 The Hacker News
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
FOE Jul 22 The Register (Security)
OpenAI admits it was the source of the agent swarm that attacked Hugging Face
FOE Jul 22 Krebs on Security
LG to Ban Residential Proxies from Smart TV Apps
FOE Jul 22 CISA KEV
CVE-2026-50522: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
FOE Jul 22 CISA KEV
CVE-2026-16232: Check Point SmartConsole Improper Authentication Vulnerability
FRIEND Jul 21 Bleeping Computer
Police dismantle Kratos phishing platform, arrest developer
FOE Jul 21 Bleeping Computer
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
FOE Jul 21 Dark Reading
Ransomware Is Accelerating, But It's Not Because of AI
FOE Jul 21 Dark Reading
Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task
FRIEND Jul 21 The Register (Security)
Cisco's open-weight bug busters take on Google and OpenAI
FOE Jul 21 Bleeping Computer
Critical SharePoint RCE flaw exploited to steal machine keys
FOE Jul 21 The Register (Security)
AI's cheatin' heart will make you weep
FOE Jul 21 EPIC
PRESS RELEASE: EPIC and the National Institute for Workers’ Rights Release White Paper on Algorithmic Unionbusting
FOE Jul 21 Bleeping Computer
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
FOE Jul 21 The Hacker News
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
FOE Jul 21 Dark Reading
Hacker Turns AI Jailbreaks Into Offensive Attack Platform
FRIEND Jul 21 SecurityWeek
Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains
FRIEND Jul 21 BrightTALK InfoSec
Reduce AI Risk with Threat Intelligence–Driven SecOps
FRIEND Jul 21 SecurityWeek
Cisco Launches Low-Cost AI Models for Source Code Security
FOE Jul 21 Bleeping Computer
Critical wp2shell WordPress flaws exploited to install webshells
FOE Jul 21 The Register (Security)
Kratos phishing-as-a-service kit loses its battle with international law enforcement
FOE Jul 21 The Hacker News
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
FRIEND Jul 21 BrightTALK InfoSec
Optimizing SOC Defense with Emerging Tech for the AI Era
FRIEND Jul 21 The Hacker News
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
FRIEND Jul 21 Professor Messer
Today’s N10-009 CompTIA Network+ Pop Quiz: The rainbow of cables
FOE Jul 21 The Hacker News
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
FOE Jul 21 The Hacker News
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
FOE Jul 21 Bleeping Computer
Closing the Identity Gaps in Critical Infrastructure Security
FOE Jul 21 The Register (Security)
AI music platform Suno hits bum note as 55M users exposed in data breach, claims infosec expert
FRIEND Jul 21 SANS Internet Storm Center
Captive Portal Detection, (Tue, Jul 21st)
FOE Jul 21 Ars Technica (Security)
Apps targeted at US troops contain Chinese and Russian code
FOE Jul 21 The Hacker News
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
FRIEND Jul 21 The Register (Security)
Intel fortifies Foundry with an actual customer: Fortinet
FOE Jul 21 Dark Reading
Choose Wisely: AI-Generated Coding Risk Varies, A Lot
FRIEND Jul 21 SecurityWeek
Empirical Security Raises $25 Million in Series A Funding
FRIEND Jul 21 SecurityWeek
SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
FRIEND Jul 21 Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: Looks good to me
FOE Jul 21 CISA Alerts
Rockwell Automation ThinManager
FOE Jul 21 CISA Alerts
Rockwell Automation 1734 POINT I/O
FOE Jul 21 CISA Alerts
Rockwell Automation 1718-AENTR/1719-AENTR
FOE Jul 21 CISA Alerts
Siemens Opcenter X
FOE Jul 21 CISA Alerts
Rockwell Automation FactoryTalk Services Platform
FOE Jul 21 CISA Alerts
Tycon Systems TPDIN-Monitor-WEB2
FOE Jul 21 CISA Alerts
Siemens IAM Client
FOE Jul 21 CISA Alerts
Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
FOE Jul 21 CISA Alerts
Rockwell Automation Studio 5000 Logix Designer
FOE Jul 21 CISA Alerts
Siemens CADRA
FOE Jul 21 CISA Alerts
Siemens SIDIS Secured SmartPlug
FOE Jul 21 CISA Alerts
CISA Adds Four Known Exploited Vulnerabilities to Catalog
FOE Jul 21 The Hacker News
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
FOE Jul 21 SecurityWeek
New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
FOE Jul 21 CSO Online
AI agents can escape sandboxes without ever breaking them
FOE Jul 21 The Hacker News
N-day is Becoming N-Hour. Patching Faster Won't Save You.
FRIEND Jul 21 SecurityWeek
CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG
FOE Jul 21 The Hacker News
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
FOE Jul 21 SecurityWeek
Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
FOE Jul 21 Schneier on Security
MIT to Become Hotbed of AI Video Surveillance
FOE Jul 21 Bleeping Computer
US seizes over 1,000 websites in FIFA World Cup piracy crackdown
FOE Jul 21 SecurityWeek
Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data
FOE Jul 21 Bleeping Computer
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
FOE Jul 21 SecurityWeek
Clover Health Investments Discloses Data Breach
FOE Jul 21 Bleeping Computer
Microsoft shares manual fix for WSUS sync delays and timeouts
FOE Jul 21 The Hacker News
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
FOE Jul 21 SecurityWeek
Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
FOE Jul 21 SecurityWeek
Zimbra Update Patches Critical Vulnerabilities
FOE Jul 21 Bleeping Computer
Windows LegacyHive zero-day flaw gets free, unofficial patches
FOE Jul 21 The Hacker News
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
FOE Jul 21 CSO Online
White hat hacker Park Chan-am zeros in on the AI era’s key security challenges
FRIEND Jul 21 CSO Online
Context bombing heralds a new AI era of deceptive defense
FOE Jul 21 The Hacker News
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
FOE Jul 21 The Register (Security)
OVH reveals semi-secret plan to fix critical Januscape hypervisor bug with mass reboots – and an Australian crash-test dummy
FOE Jul 21 The Register (Security)
OVH reveals semi-secret plan to fix critical Januscape bug with mass reboots – and an Australian crash-test dummy
FOE Jul 21 Sophos News
July Patch Tuesday only feels endless
FRIEND Jul 21 Sophos News
Sophos Named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services for Midmarket 2026
FOE Jul 21 CISA KEV
CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
FOE Jul 21 CISA KEV
CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability
FOE Jul 21 CISA KEV
CVE-2026-60137: WordPress Core SQL Injection Vulnerability
FOE Jul 20 Bleeping Computer
Estée Lauder discloses data breach via Oracle E-Business flaw
FOE Jul 20 Bleeping Computer
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
FOE Jul 20 Bleeping Computer
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
FOE Jul 20 The Register (Security)
Attackers pummel critical WordPress vuln to create all sorts of mischief
FRIEND Jul 20 EFF Deeplinks
Protect Your Privacy with California's DROP Tool
FOE Jul 20 Dark Reading
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
FOE Jul 20 Bleeping Computer
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
FOE Jul 20 Bleeping Computer
JadePuffer agentic attacks now target AI model data with ransomware
FOE Jul 20 EPIC
Section 230 Does Not Immunize App Stores for Selling Illegal Casino Chips, EPIC Tells 9th Circuit
FRIEND Jul 20 Dark Reading
Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push
FOE Jul 20 CSO Online
ServiceNow’s sandbox escape RCE hole now exploited in the wild
FOE Jul 20 The Register (Security)
Scammers impersonate FBI on social media, prey on crime victims
FOE Jul 20 The Intercept (Privacy)
U.S. Official: Iran Attacks Injured “Far More” Troops Than Pentagon Admits
FOE Jul 20 Dark Reading
25 Years After Code Red: What the Worm Era Can Teach Us About AI Security
FOE Jul 20 EFF Deeplinks
An Explosion of Surveillance Towers is Coming to U.S. Borders, Costing Over $1 Billion
FOE Jul 20 The Register (Security)
Malicious cloud customers can bring down the power grid
FOE Jul 20 Dark Reading
CISOs Feel the Heat Over AI Risk
FRIEND Jul 20 EFF Deeplinks
“Stealth Crawlers” Are Not a Threat to the Open Web. Bills Targeting Them Would Be.
FOE Jul 20 The Register (Security)
Frontier LLMs couldn't help Hugging Face fight off evil agents
FOE Jul 20 SANS Internet Storm Center
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
FOE Jul 20 Dark Reading
Attackers Combo Up Evasion Tactics for BEC Phishing
FOE Jul 20 The Hacker News
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
FOE Jul 20 Bleeping Computer
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
FOE Jul 20 The Hacker News
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
FRIEND Jul 20 BrightTALK InfoSec
Preparing Security Analysts for the Reality of Modern Security Operations
FOE Jul 20 The Register (Security)
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
FRIEND Jul 20 SecurityWeek
Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software
FOE Jul 20 CSO Online
AI adoption and business acceleration are changing the expectations of technology risk management
FOE Jul 20 The Hacker News
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
FOE Jul 20 SecurityWeek
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
FRIEND Jul 20 Bleeping Computer
An AI SOC Evaluation Guide for Security Leaders
FOE Jul 20 Ars Technica (Security)
Pay up or not? Ransomware surge has victims facing tough choices
FRIEND Jul 20 Dark Reading
Cybersecurity Keeps Events 'Uneventful'
FOE Jul 20 The Hacker News
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
FOE Jul 20 SecurityWeek
OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability
FOE Jul 20 CSO Online
Patch now: WordPress REST API bug allows remote code execution
FOE Jul 20 The Hacker News
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
FOE Jul 20 CSO Online
New ACR Stealer campaigns use WebDAV, MSHTA to evade detection
FRIEND Jul 20 Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: A work of art
FOE Jul 20 Bleeping Computer
Hugging Face discloses breach linked to autonomous AI agent
FOE Jul 20 SecurityWeek
New Index Tracks Material Breaches — And Refuses to Add Up the Losses
FOE Jul 20 The Hacker News
Mythos Didn't Break Your Security Program. Your Exposure Window Could.
FOE Jul 20 SecurityWeek
Ernst & Young Data Breach Affects Personal, Financial Information
FOE Jul 20 Schneier on Security
On Flock License Plate Tracking Cameras
FOE Jul 20 Bleeping Computer
Microsoft confirms Windows Server Update Services sync delays
FRIEND Jul 20 SecurityWeek
Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
FRIEND Jul 20 Bleeping Computer
Windows KB5121767 OOB update fixes shutdowns on some Dell PCs
FOE Jul 20 The Intercept (Privacy)
Google Is Censoring Reviews of ICE Detention Centers
FOE Jul 20 SecurityWeek
Hugging Face Hacked in Autonomous AI Attack
FOE Jul 20 Bleeping Computer
Critical ServiceNow code execution flaw now exploited in attacks
FOE Jul 20 The Hacker News
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
FOE Jul 20 The Hacker News
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
FOE Jul 20 The Intercept (Privacy)
Hegseth’s War Department Slashed Civilian Protection Staff, Brought in AI Assessments
FOE Jul 20 SecurityWeek
Chrome 150 Update Patches Severe Memory Safety Bugs
FOE Jul 20 CSO Online
SOCs face a human challenge as AI speeds alerts and threats
FRIEND Jul 20 CSO Online
Claude Mythos FAQ: Capabilities, access, competitors, implications
FOE Jul 20 Risky Business News
Risky Bulletin: Hacker wipes Romania's entire land registry database
FOE Jul 20 The Hacker News
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
FOE Jul 20 SecurityWeek
WP2Shell WordPress Vulnerabilities Exploited in the Wild
FOE Jul 20 The Hacker News
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
FRIEND Jul 20 Sophos News
Sophos ZTNA unlocks SaaS app control and so much more
FOE Jul 20 Sophos News
In code we trust? Why the most trusted software receives the least scrutiny.
FRIEND Jul 20 Sophos News
Sophos joins Anthropic's Project Glasswing
FOE Jul 19 The Hacker News
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
FOE Jul 19 The Register (Security)
Connecting AI agents to outside services explodes the risk radius
FOE Jul 19 SANS Internet Storm Center
Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)
FOE Jul 19 Bleeping Computer
Hackers abuse ViPNet software to target Russian govt agencies
FOE Jul 19 The Hacker News
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
FOE Jul 19 The Hacker News
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
FOE Jul 18 Bleeping Computer
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
FOE Jul 18 Bleeping Computer
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
FOE Jul 18 Bleeping Computer
Microsoft warns of surge in ACR Stealer attacks on customers
FRIEND Jul 18 Bleeping Computer
The Future of Age Verification: Your Face Never Leaves Your Device
FOE Jul 17 The Hacker News
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
FOE Jul 17 Bleeping Computer
Abbott Laboratories probes two cyber incidents amid extortion claims
FRIEND Jul 17 Professor Messer
Professor Messer’s N10-009 Network+ Study Group – July 2026
FOE Jul 17 The Hacker News
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
FOE Jul 17 Dark Reading
Inc Ransomware Exploits SonicWall SMA Zero-Days
FOE Jul 17 The Hacker News
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
FRIEND Jul 17 BrightTALK InfoSec
From Vendors to Digital Workers: Verifying Trust in the Agentic Supply Chain
FOE Jul 17 Bleeping Computer
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
FRIEND Jul 17 CSO Online
OnlyFans performers become unlikely allies of CISOs in securing websites
FOE Jul 17 The Hacker News
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
FRIEND Jul 17 EFF Deeplinks
Victory! Flock Ends Rollout of Audio “Distress Detection” of Human Voices
FRIEND Jul 17 EFF Deeplinks
Your Vision. Your Legacy. Your Future.
FOE Jul 17 Dark Reading
The Real AI Threat Is Blind Trust
FOE Jul 17 The Hacker News
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
FOE Jul 17 The Register (Security)
AI spam filters are getting suckered by old-school text salting
FOE Jul 17 BrightTALK InfoSec
Scaling Operational Resilience Against AI-Driven Threats
FRIEND Jul 17 EFF Deeplinks
How the Watch Dogs Video Game Series Mirrored and Predicted Real-World Digital Rights Issues
FOE Jul 17 Bleeping Computer
Ernst & Young discloses data breach after support system hack
FOE Jul 17 CSO Online
Google must open Android to rival AI agents, EU orders
FOE Jul 17 SecurityWeek
In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint
FOE Jul 17 Bleeping Computer
Inside the Search for "Clean" Residential Proxies for Carding
FOE Jul 17 The Hacker News
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
FRIEND Jul 17 Dark Reading
Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear
FOE Jul 17 SecurityWeek
Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive
FRIEND Jul 17 Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: Maybe you should lay down
FOE Jul 17 The Register (Security)
Attackers target critical FortiSandbox flaws as CISA issues patch order
FRIEND Jul 17 Dark Reading
Google Bets 'Agentic Defense' Strategy Can Outpace Attackers
FOE Jul 17 The Hacker News
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
FRIEND Jul 17 SecurityWeek
Beacon Security Raises $13 Million for Security Data Platform
FOE Jul 17 The Hacker News
The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?
FRIEND Jul 17 SecurityWeek
Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday
FOE Jul 17 Bleeping Computer
New Windows LegacyHive zero-day gives hackers admin privileges
FRIEND Jul 17 Schneier on Security
Details of Alan Turing’s Voice Encryption System
FOE Jul 17 The Hacker News
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
FOE Jul 17 The Register (Security)
Google fixing Android lock screen bug that lets Gemini send SMS without a PIN
FOE Jul 17 Bleeping Computer
Windows Server 2022 reach end of mainstream support in 90 days
FOE Jul 17 SecurityWeek
Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei
FOE Jul 17 CSO Online
The SaaS blind spot: Why security teams can’t get inside their own apps
FOE Jul 17 The Hacker News
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
FOE Jul 17 The Hacker News
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
FOE Jul 17 CSO Online
Fake TTF files deliver stealthy malware in global phishing campaign
FRIEND Jul 17 SecurityWeek
Risk Ledger Raises $32 Million in Series B Funding
FOE Jul 17 Bleeping Computer
US charges two over laundering $43 million from investment fraud
FOE Jul 17 SecurityWeek
Fresh SharePoint Vulnerability Exploited Soon After Disclosure
FOE Jul 17 Bleeping Computer
CISA urges immediate action on actively exploited Fortinet flaws
FOE Jul 17 CSO Online
Senior executives are killing your shadow AI strategy
FOE Jul 17 The Hacker News
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
FOE Jul 17 SecurityWeek
Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack
FRIEND Jul 17 The Register (Security)
South Korea making its own security-centric AI model
FOE Jul 16 The Register (Security)
OpenAI admits GPT-5.6 occasionally deletes files – but it's an 'honest mistake'
FOE Jul 16 Bleeping Computer
New ClickLock macOS malware traps users into revealing login password
FOE Jul 16 Bleeping Computer
Coca-Cola says Fairlife ransomware attack halts US dairy production
FOE Jul 16 Dark Reading
Agentic AI Is Untamable: Ask the Right Security Questions
FOE Jul 16 EPIC
PRESS RELEASE: Coalition Asks Federal Court to Enforce Landmark Ruling Blocking Unlawful SAVE System
FOE Jul 16 The Register (Security)
Researcher poisons open-weight AI model for under $100
FOE Jul 16 Dark Reading
1M+ Emails Use Hidden Text to Dupe AI Security Filters
FOE Jul 16 Ars Technica (Security)
Now, even Russia's most elite hackers are using Clickfix to infect devices
FOE Jul 16 Bleeping Computer
Claude Chrome extension flaw lets malicious extensions trigger AI actions
FOE Jul 16 Bleeping Computer
New OkoBot framework deploys 20 payloads to steal data, crypto
FOE Jul 16 The Intercept (Privacy)
ICE Officers at Maine Shooting Scene Were Wearing Body Cameras. They Were Not Turned On.
FOE Jul 16 CSO Online
Zoom patches account takeover hole
FOE Jul 16 The Hacker News
Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack
FOE Jul 16 The Hacker News
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
FOE Jul 16 The Register (Security)
C'mon, just copy this text string and paste it into your macOS Terminal – it'll fix your computer, honest
FOE Jul 16 SecurityWeek
Legacy Systems, Real-World Impacts: The Reality of OT Security
FRIEND Jul 16 Professor Messer
Today’s SY0-701 CompTIA Security+ Pop Quiz: I’m very familiar
FRIEND Jul 16 Schneier on Security
Protecting Privacy in an AI Era
FOE Jul 16 Bleeping Computer
AI Agents Broke the Security Playbook. Here's What Replaces It.
FOE Jul 16 Bleeping Computer
23andMe to pay $18 million in new genetics data breach settlement
FOE Jul 16 The Hacker News
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
FOE Jul 16 SecurityWeek
Two Scattered Spider Hackers Sentenced to Jail in UK
FOE Jul 16 SecurityWeek
AI Data Centers Are Being Built Faster Than They Can Be Secured
FOE Jul 16 The Hacker News
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
FOE Jul 16 The Register (Security)
Brit Scattered Spider duo handed tickets to prison over Transport for London attack
FOE Jul 16 SecurityWeek
‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
FOE Jul 16 The Hacker News
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
FOE Jul 16 Bleeping Computer
Scattered Spider members behind TfL hack get five years in prison
FOE Jul 16 CSO Online
CISA urges immediate SharePoint hardening as exploits mount
FRIEND Jul 16 Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: The map is not working
FOE Jul 16 CISA Alerts
CISA Adds Three Known Exploited Vulnerabilities to Catalog
FOE Jul 16 CISA Alerts
NASA Core Flight System (cFS) Health & Safety (HS) Application
FOE Jul 16 CISA Alerts
SALTO ProAccess Space
FOE Jul 16 CISA Alerts
Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
FOE Jul 16 CISA Alerts
Rockwell Automation Flex 5000 Adapter
FOE Jul 16 CISA Alerts
Rockwell Automation FactoryTalk DataMosaix
FOE Jul 16 CISA Alerts
Rockwell Automation Arena
FOE Jul 16 CISA Alerts
Siemens SICAM 8
FOE Jul 16 CISA Alerts
Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix
FOE Jul 16 CISA Alerts
AutomationDirect Productivity Suite
FOE Jul 16 Bleeping Computer
Windows 11 24H2 Home and Pro reach end of support in 90 days
FOE Jul 16 The Hacker News
20+ Hijacked Government Websites Became
an Attack Channel
FOE Jul 16 The Hacker News
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
FOE Jul 16 The Register (Security)
Windows 10 refuses to die, and the security bill is coming due
FRIEND Jul 16 SecurityWeek
Oak Emerges From Stealth Mode With $60 Million in Funding
FOE Jul 16 The Hacker News
Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor
FOE Jul 16 Bleeping Computer
CISA orders feds to patch actively exploited Oracle flaw by Saturday
FOE Jul 16 SecurityWeek
Splunk, Zoom Patch Critical Vulnerabilities
FRIEND Jul 16 CSO Online
CISA urges software vendors to formalize vulnerability disclosure programs
FOE Jul 16 Bleeping Computer
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
FRIEND Jul 16 The Hacker News
AI Can Find Bugs, But Human Knowledge Still Proves Them
FOE Jul 16 The Register (Security)
Telegram shortlinks knocked offline over sanctioned VPN connection
FOE Jul 16 Bleeping Computer
New Spirals ransomware encrypts victim network in under 24 hours
FOE Jul 16 CSO Online
When AI gets a body, it inherits an attack surface
FOE Jul 16 The Hacker News
Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide
FOE Jul 16 EFF Deeplinks
EFF and ARTICLE 19 Submission to the European Commission on the DSA Trusted Flagger Guidelines
FOE Jul 16 SecurityWeek
F5 Patches Multiple NGINX, BIG-IP Vulnerabilities
FOE Jul 16 CSO Online
The executive profile your security team isn’t defending
FOE Jul 16 SecurityWeek
China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans
FRIEND Jul 16 The Hacker News
OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol
FOE Jul 16 SecurityWeek
Old UEFI Shims Expose Systems to Secure Boot Bypass
FOE Jul 16 Risky Business News
Srsly Risky Biz: Ransomware Uses AI To Amp Up Negotiations
FOE Jul 16 The Hacker News
Zoom Patches Critical Windows Flaw That Could Enable Account Takeover
FOE Jul 16 The Register (Security)
Law firm insisted on one password to rule them all
FOE Jul 16 Dark Reading
Police Disrupt a €140M Cyber Fraud Ring in Spain
FOE Jul 16 CSO Online
Flaw surge fuels need for CISOs to rethink vulnerability management
FOE Jul 16 SecurityWeek
Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day
FOE Jul 16 The Register (Security)
Tech support scam caused massive data breach at Australian airline Qantas
FOE Jul 16 SecurityWeek
Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities
FOE Jul 16 The Register (Security)
Cyberattack threatens utterly critical infrastructure in Japan: KFC
FOE Jul 16 CISA KEV
CVE-2026-58644: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
FOE Jul 16 CISA KEV
CVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerability
FOE Jul 15 Bleeping Computer
Dutch police bust investment fraud ring stealing over €100 million
FOE Jul 15 Dark Reading
Forgotten Bootloaders Expose Secure Boot Blind Spot
FOE Jul 15 EFF Deeplinks
California Steps Back From Dangerous Expansion of its Age-Gating Law
FOE Jul 15 CSO Online
NPM ecosystem hit with two new supply chain compromises
FOE Jul 15 Dark Reading
Identity Attacks Overtake Exploits as Top Ransomware Cause
FOE Jul 15 Bleeping Computer
Zoom warns of critical account takeover vulnerability
FOE Jul 15 Ars Technica (Security)
Windows 0-day drops the same day Microsoft releases record number of patches
FOE Jul 15 EFF Deeplinks
Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features
FOE Jul 15 The Hacker News
TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
FOE Jul 15 Bleeping Computer
Google Gemini CLI abused as a hacking agent, malware botnet operator
FRIEND Jul 15 Dark Reading
Guten Tag, Bonjour, Hola to Our European Cyber Defenders!
FOE Jul 15 The Intercept (Privacy)
Intel Pick Jay Clayton Won’t Tell Congress Whether Trump Ordered Subpoenas of NYT Journalists
FOE Jul 15 EPIC
EPIC Seeks Records on USDA’s Secretive Palantir Contracts Meant to Detect SNAP Fraud
FOE Jul 15 Dark Reading
Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife
FOE Jul 15 EFF Deeplinks
🚫 Don't Let Congress Age-Gate the Internet | EFFector 38.13
FOE Jul 15 Bleeping Computer
​ ​AsyncAPI npm packages infected with credential-stealing malware
FOE Jul 15 The Hacker News
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
FOE Jul 15 Dark Reading
Claude Flaw Automatically Sends Malicious Prompts to AI Agents
FOE Jul 15 The Register (Security)
CISA sounds alarm over trio of exploited SharePoint flaws
FOE Jul 15 EPIC
EPIC Again Urges USDA to Abandon Proposed National SNAP Database That Threatens Privacy
FOE Jul 15 SecurityWeek
Unpatched Cursor Vulnerability Exposes Users to Code Execution
FOE Jul 15 SecurityWeek
CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities
FOE Jul 15 Bleeping Computer
We built a vulnerability vending machine: AI tokens in, zero-days out
FRIEND Jul 15 Black Hills Information Security
KAPE 101: A Kroll Artifact Parser and Extractor Cheatsheet
FOE Jul 15 The Register (Security)
Microsoft cancels Patch Tuesday for some Dell users over surprise shutdowns, overheating devices
FOE Jul 15 The Hacker News
Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
FOE Jul 15 Dark Reading
2-Click Cursor Exploit Enables Dev Environment Takeover
FOE Jul 15 SecurityWeek
Windows Bind Link Attacks Can Hide Malware From EDR Tools
FOE Jul 15 CSO Online
New Windows Bind Link techniques let attackers evade EDR, security controls
FOE Jul 15 The Register (Security)
LegacyHive: 'Bone-shattering' zero-day from Microsoft's serial tormentor not the haymaker that was promised
FRIEND Jul 15 SecurityWeek
Virtual Event Today: Cloud & Data Security Summit
FRIEND Jul 15 CSO Online
White House launches AI-driven vulnerability clearinghouse to speed cyber remediation
FOE Jul 15 CSO Online
New bugs in Claude for Chrome allow extensions to abuse AI privileges
FRIEND Jul 15 Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: Clap on
FOE Jul 15 CISA Alerts
CISA Adds Two Known Exploited Vulnerabilities to Catalog
FRIEND Jul 15 CISA Alerts
Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers
FOE Jul 15 SecurityWeek
US Charges Russian Individuals and Firms for Running Cybercrime Services
FOE Jul 15 The Hacker News
SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.
FOE Jul 15 The Hacker News
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
FRIEND Jul 15 The Hacker News
New Webinar: Closing the Approval Gap in AI-Era Ad Tech
FOE Jul 15 Schneier on Security
A Video Screen That Is Also a Camera
FOE Jul 15 SecurityWeek
Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow
FOE Jul 15 The Hacker News
Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution
FRIEND Jul 15 SecurityWeek
White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative
FOE Jul 15 CSO Online
When 80,000 fans log on at once: The 2026 World Cup’s unique cybersecurity issues
FOE Jul 15 SecurityWeek
Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption
FOE Jul 15 Bleeping Computer
CISA warns admins to patch actively exploited SharePoint flaws
FOE Jul 15 SecurityWeek
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell
FOE Jul 15 The Hacker News
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
FOE Jul 15 CSO Online
Cybersecurity needs more prevention and less reliance on cure
FOE Jul 15 Bleeping Computer
Microsoft: Some Dell PCs shut down after recent Windows updates
FOE Jul 15 Dark Reading
Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits
FOE Jul 15 Bleeping Computer
US charges alleged operators of Russian bulletproof hosting service
FOE Jul 15 SecurityWeek
Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
FRIEND Jul 15 CSO Online
7 skills and traits of elite security engineers
FOE Jul 15 The Hacker News
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
FOE Jul 15 SecurityWeek
SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits
FRIEND Jul 15 CSO Online
Microsoft is forcing an enterprise transition to passkeys
FOE Jul 15 CSO Online
Patch Tuesday roundup: Microsoft fixes a monthly record 569 holes; SAP patches a critical memory corruption bug
FRIEND Jul 15 SANS Internet Storm Center
Recent DShield SIEM Update, (Tue, Jul 14th)
FRIEND Jul 15 Dark Reading
Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal
FOE Jul 15 Sophos News
SonicWall SMA1000 vulnerabilities in active exploitation
FOE Jul 15 CISA KEV
CVE-2026-46817: Oracle E-Business Suite Improper Privilege Management Vulnerability
FOE Jul 15 CISA KEV
CVE-2023-4346: KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
FRIEND Jul 15 Sophos News
The stack had a good run. Defense systems are the future.
FOE Jul 15 Sophos News
The State of Ransomware 2026: Payments are dropping but encryption is climbing
FOE Jul 14 Ars Technica (Security)
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
FOE Jul 14 Dark Reading
Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes
FOE Jul 14 Bleeping Computer
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
FRIEND Jul 14 EFF Deeplinks
European Court: Apple Can Not Shirk Off its Interoperability Requirements
FOE Jul 14 The Register (Security)
Patchpocalypse Now: Microsoft tops last month's record with 622 Patch Tuesday CVEs
FOE Jul 14 The Hacker News
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
FOE Jul 14 Bleeping Computer
Spanish Police take down €140 million cyber fraud ring, arrest four
FOE Jul 14 Dark Reading
6 GHz Wi-Fi Flaws Could Disrupt Critical Systems
FOE Jul 14 EFF Deeplinks
Don’t Repeat NY’s 3D Printing Blunder
FOE Jul 14 Krebs on Security
Microsoft Patches a Record 570 Security Flaws
FOE Jul 14 Bleeping Computer
Nearly 300 GitHub repos pose as legit software to push malware
FOE Jul 14 SANS Internet Storm Center
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
FOE Jul 14 SecurityWeek
Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days
FRIEND Jul 14 Bleeping Computer
Microsoft releases Windows 10 KB5099539 extended security update
FOE Jul 14 SecurityWeek
Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims
FOE Jul 14 The Hacker News
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
FOE Jul 14 Bleeping Computer
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
FRIEND Jul 14 Dark Reading
Manage Vendor Risk in a Few Practical Steps
FRIEND Jul 14 Bleeping Computer
Windows 11 KB5101650 & KB5099414 cumulative updates released
FOE Jul 14 The Hacker News
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
FOE Jul 14 SecurityWeek
Adobe Patches Critical ColdFusion Vulnerabilities
FOE Jul 14 The Hacker News
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
FOE Jul 14 The Register (Security)
Welsh Doxbin admin jailed for egging on swatters from behind a screen
FOE Jul 14 Bleeping Computer
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
FRIEND Jul 14 Schneier on Security
Upcoming Speaking Engagements
FOE Jul 14 Dark Reading
Frontier AI: The Genie's Out of the Bottle, but Where's the Rulebook?
FOE Jul 14 Dark Reading
ClickFix's Mushrooming Ecosystem Demands New Defense Tactics
FOE Jul 14 Bleeping Computer
LastPass, Bitwarden users targeted with fake security alerts
FRIEND Jul 14 Professor Messer
Today’s N10-009 CompTIA Network+ Pop Quiz: I’ll fix it on the screen
FRIEND Jul 14 Bleeping Computer
You Don't Have to Run an Exploit to Know If You're Vulnerable
FOE Jul 14 SecurityWeek
7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
FOE Jul 14 The Hacker News
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
FOE Jul 14 Dark Reading
Cursor IDE Auto-Executes Malicious Code in Poisoned Repos
FOE Jul 14 SecurityWeek
Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar
FRIEND Jul 14 Bleeping Computer
Microsoft Entra ID gets passkeys default authentication starting September
FOE Jul 14 Bleeping Computer
New phishing kits target Microsoft 365 accounts, evade MFA
FOE Jul 14 The Hacker News
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
FOE Jul 14 The Register (Security)
Musk promises purge after Grok Build caught sending entire repos to the cloud
FOE Jul 14 The Register (Security)
'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes
FRIEND Jul 14 Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: Recreating from scratch
FOE Jul 14 CISA Alerts
CISA Adds Four Known Exploited Vulnerabilities to Catalog
FOE Jul 14 CISA Alerts
CISA Urges SharePoint Hardening After New Exploitations
FOE Jul 14 CISA Alerts
Rockwell Automation 1715-AENTR EtherNet/IP Adapter
FOE Jul 14 CISA Alerts
ABB Ability Edgenius
FOE Jul 14 CISA Alerts
ABB Advant Master Online Builder
FOE Jul 14 CISA Alerts
ABB T-MAC Plus
FOE Jul 14 The Hacker News
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
FOE Jul 14 Bleeping Computer
SAP warns of critical flaws in NetWeaver and Commerce Cloud
FRIEND Jul 14 The Hacker News
How Pentera Turns AI Security Workflows into Validation Engines
FOE Jul 14 The Hacker News
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
FOE Jul 14 SecurityWeek
SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud
FOE Jul 14 Schneier on Security
Vulnerability in FIFA’s Network
FOE Jul 14 The Register (Security)
Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websites
FOE Jul 14 SecurityWeek
US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers
FOE Jul 14 CSO Online
Phishing for dummies: Forg365 lowers barrier to M365 account takeovers
FOE Jul 14 Bleeping Computer
US sanctions VPN, malware providers for enabling ransomware attacks
FRIEND Jul 14 SecurityWeek
Valarian Raises $50 Million for Sovereign Infrastructure Control Layer
FOE Jul 14 SecurityWeek
Multiple Jscrambler Packages Impacted by Supply Chain Attack
FOE Jul 14 The Hacker News
Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads
FOE Jul 14 CSO Online
AI incidents need a new playbook. Here’s how to build one
FOE Jul 14 The Hacker News
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
FOE Jul 14 The Hacker News
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
FOE Jul 14 CSO Online
AI-powered breaches provide wake-up call for incident response
FRIEND Jul 14 SecurityWeek
Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules
FOE Jul 14 The Hacker News
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
FOE Jul 14 CSO Online
Governments to enterprises: Improve your router security hygiene
FOE Jul 14 CSO Online
US authorities warn of Russian attacks on critical infrastructure
FRIEND Jul 14 Sophos News
Sophos Protected Browser Extension: Protection and visibility without changing browsers
FOE Jul 14 CISA KEV
CVE-2026-56164: Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
FOE Jul 14 CISA KEV
CVE-2026-56155: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
FOE Jul 14 CISA KEV
CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
FOE Jul 13 Dark Reading
Weak Security Continues to Fuel Russian Cyberattacks
FOE Jul 13 Ars Technica (Security)
The US government warns that Russia state hackers are coming after your router
FOE Jul 13 Bleeping Computer
Japan's largest taxi operator shuts systems after cyberattack
FOE Jul 13 Bleeping Computer
Hackers backdoor Jscrambler npm package with infostealer malware
FOE Jul 13 Bleeping Computer
New CrashStealer malware poses as Apple crash reporting tool
FOE Jul 13 Dark Reading
'Yellow Teams' Are Defining the Future of AI Security
FRIEND Jul 13 EPIC
EPIC Urges D.C. Council to Strengthen Proposed Government Data Privacy and Protection Act
FOE Jul 13 The Hacker News
CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
FOE Jul 13 EFF Deeplinks
Sony Nerfs Videogame Ownership
FOE Jul 13 The Hacker News
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
FOE Jul 13 Dark Reading
GigaWiper Lets Threat Actors Choose Their Own Destructive Attack
FOE Jul 13 The Register (Security)
EU and UK officially blame Russian spies for cyberattack on Poland's power grid
FOE Jul 13 Bleeping Computer
CISA warns of actively exploited RCE flaws in Joomla extensions
FRIEND Jul 13 Ars Technica (Security)
Now, defenders are embracing the prompt injection, too
FOE Jul 13 The Hacker News
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
FOE Jul 13 Krebs on Security
Lessons Learned from CISA’s Recent GitHub Leak
FRIEND Jul 13 SecurityWeek
Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption
FOE Jul 13 Bleeping Computer
Lidl discloses online shop breach after service provider hack
FRIEND Jul 13 Bleeping Computer
Breach at the Beach: Play the Ultimate Entra ID CTF
FRIEND Jul 13 BrightTALK InfoSec
The Five-Layer Stack Behind Every Defensible AI System
FOE Jul 13 The Hacker News
New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email
FRIEND Jul 13 EPIC
EPIC, CFA, Fairplay Submit Recommendations Ahead of Potential Rulemaking for Colorado Automated Decision-Making and Chatbot Laws
FOE Jul 13 Bleeping Computer
UK charges suspects linked to Russian Coms call spoofing platform
FOE Jul 13 The Hacker News
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
FRIEND Jul 13 Dark Reading
Turning the Tables on Email Scammers With 'ScamBuster'
FRIEND Jul 13 SecurityWeek
Cybersecurity M&A Roundup: 37 Deals Announced in June 2026
FOE Jul 13 The Register (Security)
World Cup grudge attackers may have scored Argentine FA access via year-old infostealer infection
FOE Jul 13 CSO Online
RabbitMQ flaws expose OAuth secrets, risk complete takeover of the broker
FRIEND Jul 13 Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: Many colors to choose from
FOE Jul 13 CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog
FOE Jul 13 CISA Alerts
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
FOE Jul 13 SecurityWeek
RabbitMQ Vulnerability Threatens Enterprise Systems
FOE Jul 13 The Hacker News
Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling
FRIEND Jul 13 The Hacker News
Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots
FOE Jul 13 Bleeping Computer
EU sanctions Russian GRU military hackers over cyberattacks
FOE Jul 13 The Hacker News
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory
FOE Jul 13 Schneier on Security
AI Data Centers and the Concentration of Wealth
FOE Jul 13 The Register (Security)
Progress orders emergency ShareFile server shutdown over mystery security threat
FOE Jul 13 SecurityWeek
Zimbra Patches Critical Code Execution Vulnerability
FOE Jul 13 SecurityWeek
EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign
FOE Jul 13 CSO Online
Jurassic Park, cybersecurity and the dangerous myth of control
FOE Jul 13 Bleeping Computer
US and allies warn of Russian critical infrastructure attacks
FOE Jul 13 SecurityWeek
Organizations Warned of Exploited Joomla Extension Vulnerabilities
FOE Jul 13 CSO Online
Your AI risk register is not an incident response plan
FOE Jul 13 SecurityWeek
Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns
FOE Jul 13 SecurityWeek
Centers Laboratory Data Breach Affects 540,000 Individuals
FOE Jul 13 The Hacker News
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
FOE Jul 13 CSO Online
Can AI narrow cybersecurity’s class divide?
FOE Jul 13 The Hacker News
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
FOE Jul 13 SANS Internet Storm Center
Someone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th)
FOE Jul 13 Bleeping Computer
OpenAI temporarily relaxes GPT-5.6 Sol usage limits
FRIEND Jul 13 Sophos News
Sophos Firewall v22 MR2 is now available
FOE Jul 13 CISA KEV
CVE-2008-4128: Cisco IOS Cross-Site Request Forgery Vulnerability
FOE Jul 12 Bleeping Computer
Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time
FOE Jul 12 Bleeping Computer
RedHook Android malware now uses Wireless ADB for shell access
FOE Jul 12 The Intercept (Privacy)
Company That Bragged It Could Track U.S. Spies Hired to Investigate “Havana Syndrome”
FOE Jul 11 The Hacker News
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
FOE Jul 11 The Hacker News
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
FOE Jul 11 SecurityWeek
Ghost Accounts Abuse GitHub API in Mass Recon Campaign
FOE Jul 11 Bleeping Computer
Australia warns of global campaign targeting vulnerable CMS platforms
FRIEND Jul 11 SANS Internet Storm Center
Wireshark 4.6.7 Released, (Sat, Jul 11th)
FOE Jul 11 Bleeping Computer
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
FOE Jul 11 The Hacker News
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
FOE Jul 10 Bleeping Computer
New U-Boot flaws could enable stealthy firmware attacks
FOE Jul 10 Schneier on Security
Friday Squid Blogging: “Squidbleed” Vulnerability
FOE Jul 10 Dark Reading
Frontier AI: The Genie's Out of the Bottle, But Where's the Rulebook?
FRIEND Jul 10 Dark Reading
Jen Ellis: Connecting Cyber Community With Political Machinery
FOE Jul 10 Bleeping Computer
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
FOE Jul 10 The Register (Security)
Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package
FOE Jul 10 The Hacker News
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
FOE Jul 10 Dark Reading
Cybercriminals Flock to Healthcare Businesses as Attacks Surge
FOE Jul 10 Bleeping Computer
Police suspects Dutch hackers were involved in Odido breach
FOE Jul 10 The Hacker News
URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
FOE Jul 10 Bleeping Computer
Progress urges ShareFile admins to shut down servers over “credible” threat
FOE Jul 10 The Hacker News
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
FOE Jul 10 Bleeping Computer
Hackers exploit critical auth bypass in Gitea Docker image
FOE Jul 10 Bleeping Computer
Money launderer accused of stealing seized crypto while in prison
FOE Jul 10 SecurityWeek
In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops
FRIEND Jul 10 EFF Deeplinks
Building Our Future Together
FOE Jul 10 The Hacker News
Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched
FOE Jul 10 CSO Online
EU extends mass scanning of messages without a warrant
FOE Jul 10 CSO Online
CrowdStrike identifies five new prompt injection threats to AI
FOE Jul 10 The Hacker News
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
FOE Jul 10 Bleeping Computer
The Replicant in Your Directory: AI Agents and the Identity Security Gap
FOE Jul 10 Dark Reading
Fresh ATM Crypto Software Bugs: Jackpot or Bust?
FOE Jul 10 Dark Reading
More Countries Jump on the Social Media Ban Wagon
FRIEND Jul 10 EPIC
PRESS RELEASE: EPIC Applauds Introduction of Privacy-Centered Federal Chatbot Bill
FOE Jul 10 EFF Deeplinks
Automated Moderation Is Here to Stay—Accountability Must Keep Pace
FOE Jul 10 The Hacker News
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
FOE Jul 10 Dark Reading
AI Coding: Do Security Risks Outweigh Productivity Gains?
FOE Jul 10 SecurityWeek
Third US Security Expert Sentenced to Prison for Helping Ransomware Gang
FOE Jul 10 The Register (Security)
Fashion mart Miinto unzips breach details, warns shoppers to watch for phisherfolk
FOE Jul 10 CISA Alerts
CISA Adds Two Known Exploited Vulnerabilities to Catalog
FRIEND Jul 10 Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: A keyboard with two keys
FOE Jul 10 SecurityWeek
China, India-Linked Hackers Both Targeted Same Pakistani Police Force
FOE Jul 10 The Hacker News
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
FOE Jul 10 Bleeping Computer
Zimbra urges customers to patch critical web client XSS flaw
FRIEND Jul 10 The Hacker News
From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale
FOE Jul 10 The Hacker News
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
FOE Jul 10 SecurityWeek
Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers
FOE Jul 10 Schneier on Security
AI Surveillance and Social Progress
FOE Jul 10 The Hacker News
Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking
FOE Jul 10 The Hacker News
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
FOE Jul 10 The Register (Security)
Scot NHS Trust probes email stuffup involving maternity patients' data
FOE Jul 10 SecurityWeek
GigaWiper Combines Multiple Malware for System-Level Sabotage
FOE Jul 10 SANS Internet Storm Center
"Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th)
FOE Jul 10 The Hacker News
Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets
FOE Jul 10 CSO Online
The business case for burning down security debt: A practical approach for CISOs
FOE Jul 10 CSO Online
Microsoft uncovers GigaWiper, a backdoor designed for destruction on demand
FOE Jul 10 SecurityWeek
‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism
FOE Jul 10 Bleeping Computer
Former ransomware negotiator gets 4 years for BlackCat attacks
FOE Jul 10 The Hacker News
Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks
FOE Jul 10 SecurityWeek
Network of 200 GitHub Repositories Used for Malware Infection
FOE Jul 10 CSO Online
Check Point CTO Jonathan Zanger sees AI elevating the value of cyber
FOE Jul 10 Risky Business News
Risky Bulletin: India bans app used to hack e-rickshaws in viral videos
FOE Jul 10 The Register (Security)
Microsoft warns customers AI will mean busier Patch Tuesdays
FOE Jul 10 CISA KEV
CVE-2026-48939: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
FRIEND Jul 10 Sophos News
Sophos named a 2026 Gartner® Peer Insights™ Customers’ Choice for Email Security
FOE Jul 09 CSO Online
AI coding tool hole illustrates a big problem with human in the loop
FOE Jul 09 The Register (Security)
An unnamed US county – perhaps in Ohio – paid $1M extortion demand to cybercriminals
FOE Jul 09 Bleeping Computer
OpenMandriva Linux says contributor tried to sabotage the project
FRIEND Jul 09 Professor Messer
Professor Messer’s CompTIA A+ 220-1202 Study Group – July 2026
FOE Jul 09 EFF Deeplinks
"We Want Texans to Know Their Rights": Q&A with Mayday Health on the Impact of Surveillance on Abortion Care
FOE Jul 09 EFF Deeplinks
The House Passed The KIDS Act—The Senate Should Reject It
FOE Jul 09 Ars Technica (Security)
Patch for Windows Defender 0-day could allow attackers to fill hard disk
FOE Jul 09 Dark Reading
Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure
FRIEND Jul 09 EPIC
EPIC Applauds the Massachusetts Senate for Passing Platform Design Regulations
FOE Jul 09 Dark Reading
Microsoft Reins in RoguePlanet Zero-Day Threat
FOE Jul 09 Bleeping Computer
Injective SDK on npm infected with cryptocurrency wallet stealer
FOE Jul 09 Dark Reading
AI Agents Are a New Kind of Identity & Most Organizations Aren't Ready
FOE Jul 09 The Hacker News
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
FOE Jul 09 EFF Deeplinks
European Commission Chooses to Keep EU Users Locked Up Behind Big Tech’s Gates
FOE Jul 09 The Hacker News
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
FOE Jul 09 Bleeping Computer
New Helix vishing group emerges in SharePoint data theft attacks
FRIEND Jul 09 Bleeping Computer
Microsoft expects more Windows security updates from AI-discovered flaws
FRIEND Jul 09 The Hacker News
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
FOE Jul 09 The Register (Security)
EU 'Chat Control' snoopfest returns after vote to kill it falls short
FOE Jul 09 The Hacker News
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
FRIEND Jul 09 SecurityWeek
QIZ Security Raises $17 Million for Cryptographic Governance Platform
FRIEND Jul 09 Professor Messer
Today’s SY0-701 CompTIA Security+ Pop Quiz: Check the paperwork
FOE Jul 09 Bleeping Computer
New Forg365 phishing platform uses AI to target Microsoft 365 accounts
FOE Jul 09 Dark Reading
As Global Conflicts Go Digital, Businesses Need Wartime Gameplans
FRIEND Jul 09 SecurityWeek
UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge
FOE Jul 09 Bleeping Computer
The Hidden Security Risks of Reduced Summer IT Coverage
FOE Jul 09 SecurityWeek
Palo Alto Networks Patches 13 Vulnerabilities
FOE Jul 09 The Register (Security)
Microsoft closes book on Nightmare Eclipse's RoguePlanet zero-day
FOE Jul 09 Dark Reading
AI Gateways Offer Attackers the Keys to the Kingdom
FOE Jul 09 CSO Online
Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk
FOE Jul 09 CSO Online
UK cyber agency unveils AI-powered Cyber Shield to counter attacks at machine speed
FOE Jul 09 The Hacker News
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up
FOE Jul 09 SecurityWeek
12 Million Impacted by Data Breach at Japanese Telco KDDI
FRIEND Jul 09 Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: I’d like a history question
FOE Jul 09 CISA Alerts
OpenPLC v3
FOE Jul 09 CISA Alerts
Schneider Electric Easergy MiCOM Px40 Series
FOE Jul 09 CISA Alerts
Schneider Electric PowerChute Serial Shutdown
FOE Jul 09 SecurityWeek
15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google
FOE Jul 09 Schneier on Security
The Language of AI Could Change How Humans Speak
FOE Jul 09 Bleeping Computer
Microsoft to retire the OWA Light client in Exchange Server
FRIEND Jul 09 The Hacker News
Summer of Clearinghouses
FOE Jul 09 The Hacker News
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
FOE Jul 09 Privacy International
Humanless Resources? Uncovering AI recruitment software
FOE Jul 09 SecurityWeek
Microsoft Patches Defender ‘RoguePlanet’ Vulnerability
FOE Jul 09 SecurityWeek
Mount Royal University Confirms Data Stolen in Ransomware Attack
FOE Jul 09 Dark Reading
'GodDamn' Ransomware Uses BYOVD to Smite US Companies
FOE Jul 09 CSO Online
Agentic AI identity: A 6-stage maturity model for non-human identities
FOE Jul 09 Bleeping Computer
Police arrests 5,800 suspects in global anti-fraud crackdown
FOE Jul 09 EFF Deeplinks
Google's new remote attestation scheme is every bit as terrible as its old remote attestation scheme
FOE Jul 09 CSO Online
Why fixing your data architecture matters more than upgrading your detection models
FOE Jul 09 SecurityWeek
AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique
FOE Jul 09 The Hacker News
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
FOE Jul 09 Risky Business News
Srsly Risky Biz: Supreme Court Undermines Section 702
FOE Jul 09 Dark Reading
European Organizations Have a Collaboration Security Confidence Gap
FOE Jul 09 Bleeping Computer
AssuranceAmerica data breach exposes records of 6.9 million drivers
FOE Jul 09 SecurityWeek
Chrome 150 Update Patches 27 Vulnerabilities
FOE Jul 09 The Hacker News
Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images
FOE Jul 09 The Register (Security)
Thief posed as Wi-Fi fixing hero, then stole priceless trophy
FOE Jul 09 CSO Online
Lateral movement risk rises as enterprises emphasize convenience over containment
FRIEND Jul 09 SecurityWeek
8Layers Raises $2.9 Million for Identity Security Platform
FOE Jul 09 Bleeping Computer
Microsoft patches RoguePlanet Defender zero-day vulnerability
FOE Jul 09 The Hacker News
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
FOE Jul 09 SecurityWeek
Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices
FOE Jul 09 The Hacker News
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
FOE Jul 09 The Hacker News
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
FRIEND Jul 09 SANS Internet Storm Center
_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th)
FOE Jul 08 CSO Online
GitHub’s public APIs are becoming an enterprise reconnaissance tool
FOE Jul 08 The Register (Security)
Suspected Chinese snoops caught breaking into universities' Roundcube mailservers
FOE Jul 08 Dark Reading
Mexico's New Cyber Plan Faces Its First Real Test
FOE Jul 08 Bleeping Computer
Mount Royal University confirms breach as hackers claim attack
FOE Jul 08 Dark Reading
Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours
FOE Jul 08 Bleeping Computer
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
FOE Jul 08 The Register (Security)
GitHub Copilot: Sorry Dave, I can't do that harmful thing - unless you ask me in code
FOE Jul 08 Ars Technica (Security)
Google pays $250k for Linux vulnerability allowing guest VM escapes
FOE Jul 08 Bleeping Computer
Hackers exploit Roundcube flaw to spy on academic researchers
FOE Jul 08 The Hacker News
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
FOE Jul 08 Bleeping Computer
Entra passkey enrollment vishing targets Microsoft 365 users
FOE Jul 08 Dark Reading
Vidar Infostealer Hammers SMBs via Malvertising Campaign
FOE Jul 08 SecurityWeek
Accenture Confirms Data Breach After Hacker Claims Source Code Theft
FRIEND Jul 08 BrightTALK InfoSec
How to Assess AI Security
FOE Jul 08 SecurityWeek
China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors
FOE Jul 08 The Hacker News
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware
FOE Jul 08 The Hacker News
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
FOE Jul 08 Bleeping Computer
3 Ways AI Powers Service Desk Attacks and How to Prevent Them
FOE Jul 08 The Register (Security)
Bug in top AI coding agents shows that Unix-era security headaches never really die
FRIEND Jul 08 Black Hills Information Security
Finding the “Goldilocks” Zone: A Practical Approach to Alert Triage
FOE Jul 08 The Register (Security)
China tells devs to ditch Claude Code over 'backdoor code' fears
FRIEND Jul 08 SecurityWeek
Webinar Today: Why Email Security Keeps Failing
FOE Jul 08 The Hacker News
New Ghost Phishing Wave Is Breaking Traditional Email Security
FOE Jul 08 The Hacker News
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
FOE Jul 08 Krebs on Security
Felons, Fraudsters Flog Offensive Cybersecurity Startup
FOE Jul 08 SecurityWeek
Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations
FOE Jul 08 CSO Online
GitHub AI agent leaks private repositories via prompt injection attack
FRIEND Jul 08 Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: The sunset is over there
FRIEND Jul 08 Bleeping Computer
DuckDuckGo browser now blocks YouTube video ads
FOE Jul 08 CSO Online
Cybercriminals exploit India’s tax filing season with a dual-malware campaign
FOE Jul 08 The Hacker News
GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
FOE Jul 08 The Hacker News
The Verification Step Is the New ATO Battleground in 2026
FOE Jul 08 Bleeping Computer
Telco giant KDDI says data breach affects over 12 million people
FOE Jul 08 The Hacker News
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code
FOE Jul 08 Schneier on Security
Cybersecurity and the Gap Between Skill and Ability
FOE Jul 08 SecurityWeek
CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
FOE Jul 08 SecurityWeek
Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection
FOE Jul 08 Bleeping Computer
CISA orders feds to prioritize patching Langflow auth bypass flaw
FOE Jul 08 The Hacker News
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
FOE Jul 08 CSO Online
My threat feed told me it was ‘Chalubo.’ The binary disagreed
FOE Jul 08 Bleeping Computer
Ubiquiti warns of new max severity UniFi OS vulnerability
FOE Jul 08 SANS Internet Storm Center
My Stack Simulator, (Wed, Jul 8th)
FOE Jul 08 Dark Reading
State IDs for AI Agents: Will Estonia Set a Precedent?
FOE Jul 08 Bleeping Computer
CISA orders feds to patch max severity ColdFusion flaw by Friday
FOE Jul 08 Ars Technica (Security)
Hackers can use 9 of the most popular AI tools to assemble massive botnets
FRIEND Jul 08 CSO Online
13 in-demand IT security certifications for higher pay
FOE Jul 08 The Hacker News
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
FOE Jul 08 Risky Business News
Risky Bulletin: All new cars to include a camera aimed at the driver's face
FOE Jul 08 The Hacker News
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
FOE Jul 07 Bleeping Computer
Accenture confirms breach after hacker offers stolen data for sale
FOE Jul 07 CSO Online
16-year-old KVM flaw allows attackers to escape VMs and take over Linux servers
FRIEND Jul 07 Professor Messer
Professor Messer’s 220-1201 CompTIA A+ Study Group – July 2026
FOE Jul 07 CSO Online
Watch out for fake support calls in Microsoft Teams
FOE Jul 07 The Intercept (Privacy)
FBI Raided Texas Activist’s House — Then Offered Her $200,000 to Become Antifa Informant
FOE Jul 07 Dark Reading
Big Brand Jobs Scam Targets Marketing Pros' Google Accounts
FOE Jul 07 The Register (Security)
Windows is watching: Anti-piracy tool fingers Scattered Spider suspect
FOE Jul 07 Dark Reading
Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft
FRIEND Jul 07 BrightTALK InfoSec
Implement Data-Driven Security with AI and Visual Intelligence
FOE Jul 07 The Register (Security)
GitHub AI agent leaks private repos when asked nicely
FOE Jul 07 Bleeping Computer
Chinese hackers develop LONGLEASH malware to expand ORB network
FOE Jul 07 SANS Internet Storm Center
More Odd DNS Records: NIMLOC, (Tue, Jul 7th)
FOE Jul 07 SecurityWeek
County Government Reportedly Paid $1 Million to Cyber Extortion Group
FOE Jul 07 Bleeping Computer
Hidden backdoor in Tenda router firmware grants admin access
FOE Jul 07 SecurityWeek
Critical Gitea Flaw Under Active Exploitation, Researchers Warn
FOE Jul 07 The Register (Security)
CAI cloud worm gives competitors' malware the boot, then steals secrets and mines for coin
FOE Jul 07 The Hacker News
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
FOE Jul 07 The Hacker News
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
FOE Jul 07 EFF Deeplinks
Automated Moderation Is Here to Stay
FRIEND Jul 07 EFF Deeplinks
Help EFF Cut the AI Hype
FOE Jul 07 The Register (Security)
Predatorgate snoopfest victims launch €8M sueball at spyware maker
FOE Jul 07 Dark Reading
'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows
FOE Jul 07 Bleeping Computer
Spain arrests suspected member of pro-Russian hacktivist groups
FOE Jul 07 The Hacker News
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
FRIEND Jul 07 Professor Messer
Today’s N10-009 CompTIA Network+ Pop Quiz: Learn another language
FOE Jul 07 The Hacker News
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
FOE Jul 07 Bleeping Computer
The GitHub Actions Attack Pattern Your CI Security Scanners Miss
FOE Jul 07 The Hacker News
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker
FOE Jul 07 The Hacker News
Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants
FRIEND Jul 07 SecurityWeek
CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws
FOE Jul 07 The Register (Security)
Enterprise AI still smarting from leaping before looking
FOE Jul 07 SecurityWeek
Critical Adobe ColdFusion Vulnerability Exploited in Attacks
FOE Jul 07 SecurityWeek
Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks
FRIEND Jul 07 Bleeping Computer
Webinar tomorrow: Why modern email attacks require a new approach to defense
FOE Jul 07 Bleeping Computer
New Januscape Linux flaw allows VM escape on Intel, AMD devices
FRIEND Jul 07 Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: Bury it in the backyard
FOE Jul 07 CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog
FOE Jul 07 CISA Alerts
CISA Adds Three Known Exploited Vulnerabilities to Catalog
FOE Jul 07 CISA Alerts
Hitachi Energy PROMOD V
FOE Jul 07 CISA Alerts
Siemens Mendix Studio Pro
FOE Jul 07 CISA Alerts
Hitachi Energy e-mesh EMS
FOE Jul 07 CISA Alerts
Hydro-Québec Le Circuit Electrique charging station backend
FOE Jul 07 CISA Alerts
Digi International PortServer TS, Digi One SP IA
FOE Jul 07 CISA Alerts
Labcenter Proteus 9
FOE Jul 07 CISA Alerts
Siemens SINEC OS
FRIEND Jul 07 SecurityWeek
CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker
FOE Jul 07 The Hacker News
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
FOE Jul 07 The Register (Security)
Fake IT bods on Microsoft Teams coax workers into installing malware
FOE Jul 07 Schneier on Security
Google Is Suing Chinese Scammers Who Are Using Gemini
FOE Jul 07 The Register (Security)
Spain collars alleged pro-Russia hacktivist after FBI tip-off
FRIEND Jul 07 The Register (Security)
Government's cyber pledge lands 60 signatories, including M&S and, somehow, Capita
FOE Jul 07 SecurityWeek
Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems
FOE Jul 07 CSO Online
Why The Gentlemen ransomware is a test of identity and recovery controls
FRIEND Jul 07 Bleeping Computer
Microsoft to enable Windows settings backup by default for orgs
FRIEND Jul 07 SecurityWeek
Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security
FOE Jul 07 The Hacker News
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
FRIEND Jul 07 CSO Online
The modern CISO is becoming the next CFO
FOE Jul 07 Bleeping Computer
BeyondTrust warns of critical flaws in remote access software
FRIEND Jul 07 Bleeping Computer
Microsoft testing new Cloud Rebuild Windows 11 recovery feature
FOE Jul 07 The Hacker News
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
FOE Jul 07 The Hacker News
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
FRIEND Jul 07 CSO Online
Insignary Closes SBOM Accuracy Gap With Binary-Level Clarity for Regulatory Risk
FOE Jul 07 CSO Online
AI agents fall for indirect prompt injection traps
FOE Jul 07 CSO Online
Zscaler finds autonomous agents succumb to IPI traps
FOE Jul 07 CISA KEV
CVE-2026-48282: Adobe ColdFusion Path Traversal Vulnerability
FOE Jul 07 Sophos News
When AI agents look like attackers: what behavioral telemetry tells us
FOE Jul 07 CISA KEV
CVE-2026-56290: Joomlack Page Builder Improper Access Control Vulnerability
FOE Jul 07 CISA KEV
CVE-2026-55255: Langflow Authorization Bypass Through User-Controlled Key Vulnerability
FOE Jul 07 CISA KEV
CVE-2026-48908: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
FOE Jul 06 Dark Reading
'BusySnake' Infostealer Slithers into Critical Infrastructure Networks
FOE Jul 06 Dark Reading
CitrixBleed-ing Again? NetScaler Vulnerability Under Attack
FOE Jul 06 Bleeping Computer
Phishing poses as big-brand job interview to steal Google accounts
FOE Jul 06 Bleeping Computer
Fake IT support calls on Microsoft Teams push EtherRAT malware
FOE Jul 06 SecurityWeek
Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks
FOE Jul 06 The Hacker News
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
FOE Jul 06 The Hacker News
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
FOE Jul 06 The Register (Security)
EU urged to act after Pegasus infects phone of spyware inquiry MEP
FOE Jul 06 Dark Reading
JadePuffer: The First Complete LLM-Driven Ransomware Attack
FOE Jul 06 The Hacker News
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
FRIEND Jul 06 SecurityWeek
The Shift Toward Business-Aligned Risk Management
FOE Jul 06 SecurityWeek
Armored Likho APT Targeting Government, Electric Power Entities
FOE Jul 06 CSO Online
The agentic blind spots in your zero trust program
FOE Jul 06 CSO Online
Identity: The operational control plane for agentic AI
FOE Jul 06 CSO Online
Operationalizing Agentic AI: from assisted to autonomous
FRIEND Jul 06 BrightTALK InfoSec
Proving Threat Hunting ROI: Outcome-Based KPIs for the Modern SOC
FOE Jul 06 Bleeping Computer
Software Is Now Written at the Speed of Thought. Security Isn't.
FRIEND Jul 06 SANS Internet Storm Center
RCS and DNS: The NAPTR Record, (Mon, Jul 6th)
FOE Jul 06 Bleeping Computer
Max severity Adobe ColdFusion flaw now exploited in attacks
FOE Jul 06 SecurityWeek
North Korean Hackers Target Open Source Developers in Supply Chain Attacks
FOE Jul 06 The Hacker News
⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
FOE Jul 06 SecurityWeek
Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability
FOE Jul 06 The Register (Security)
Brit supermarket giant triples down on facial recog to nab shoplifters
FRIEND Jul 06 Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: Try using high test
FOE Jul 06 CSO Online
This AI agent autonomously hacked a network, adapted on the fly, and demanded a ransom
FRIEND Jul 06 The Hacker News
How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions
FOE Jul 06 SecurityWeek
Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments
FOE Jul 06 The Hacker News
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
FOE Jul 06 The Register (Security)
Moody Bible Institute breach leaves 2.3M accounts needing salvation, says cyber expert
FOE Jul 06 Schneier on Security
France to Stop Certifying Non-Quantum-Safe Encryption
FOE Jul 06 CSO Online
Single points of failure fail. The SaaS layer is not an exception
FRIEND Jul 06 The Register (Security)
Secure Unix ancestor KSOS did type safety before Rust made it cool
FOE Jul 06 CSO Online
AI isn’t closing the skills gap — it’s exposing the validation gap
FOE Jul 06 The Hacker News
New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions
FOE Jul 06 The Hacker News
New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS
FOE Jul 06 The Hacker News
Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages
FRIEND Jul 06 OWASP Blog
OWASP CVE Lite CLI Graduates to Lab Project Status
FRIEND Jul 06 CSO Online
7 cyber risk assessment gotchas to avoid
FOE Jul 06 The Hacker News
SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing
FRIEND Jul 06 Risky Business News
Risky Bulletin: Android drops PIN guessing limit from 1,800 attempts to just 20
FOE Jul 06 Sophos News
"Exploit mitigation" stalled around 2008. The attacks didn't.
FOE Jul 05 The Register (Security)
MFA-optional banks leave safe doors (and accounts) wide open for thieves to pillage
FRIEND Jul 05 Bleeping Computer
Flipper Zero firmware development continues with community help
FOE Jul 04 Bleeping Computer
JadePuffer ransomware used AI agent to automate entire attack
FOE Jul 04 The Hacker News
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
FOE Jul 04 The Hacker News
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
FOE Jul 04 The Register (Security)
Confidential computing's trust mechanism is broken. The fix may not exist
FOE Jul 04 The Register (Security)
Confidential computing's core trust mechanism is broken. The fix may not exist
FOE Jul 03 The Hacker News
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
FOE Jul 03 The Hacker News
New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
FOE Jul 03 The Hacker News
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
FOE Jul 03 Bleeping Computer
NetNut proxy network disrupted, 2 million infected devices cut off
FOE Jul 03 The Hacker News
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
FOE Jul 03 CSO Online
Microsoft 365 users fall victim to one-in-a-million password spray attack
FOE Jul 03 SecurityWeek
In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting
FOE Jul 03 The Register (Security)
AdaptHealth says attackers sweet-talked their way into cloud systems and stole patient data
FOE Jul 03 Bleeping Computer
ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit
FRIEND Jul 03 CSO Online
Adobe premieres a second Patch Tuesday each month to deliver fixes faster
FOE Jul 03 The Hacker News
Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
FOE Jul 03 Dark Reading
Chinese LLMs Broaden the Gap Between Attackers & Defenders
FOE Jul 03 The Register (Security)
NetNut cracked as Google and FBI target 2 million-device botnet
FRIEND Jul 03 Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: It’s air tight
FOE Jul 03 CSO Online
New CitrixBleed-like NetScaler flaw sees exploit attempts in the wild
FOE Jul 03 Schneier on Security
Flock Cameras Can Surveil Cars Without License Plates
FOE Jul 03 The Hacker News
European Parliament Member Investigating Spyware Was Hacked With Pegasus
FOE Jul 03 SecurityWeek
Agentic AI Used to Conduct Ransomware Attack via Langflow
FOE Jul 03 SecurityWeek
Medtronic Data Breach Impacts 3.8 Million People
FOE Jul 03 SecurityWeek
Alleged Scattered Spider Hacker Extradited to US
FOE Jul 03 SecurityWeek
Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices
FOE Jul 03 The Hacker News
PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
FOE Jul 03 SecurityWeek
Critical Cursor AI IDE Flaws Could Lead to OS-Level Remote Code Execution
FOE Jul 03 The Register (Security)
User swore hacker called General Failure had invaded his PC
FOE Jul 03 Risky Business News
Risky Bulletin: FatFs bugs enable physical access attacks on a load of devices
FOE Jul 03 Bleeping Computer
Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says
FOE Jul 03 Bleeping Computer
Claude Fable relaunch disappoints users with nerfed performance
FOE Jul 02 The Register (Security)
Dev says Google warned him about account hijack – then charged him $11,000 anyway
FOE Jul 02 Dark Reading
Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs
FOE Jul 02 The Register (Security)
Startup sues Palo Alto Networks' Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage
FRIEND Jul 02 BrightTALK InfoSec
Translate Security Operations Metrics into Business Risk Intelligence
FOE Jul 02 Ars Technica (Security)
Newly discovered PamStealer isn't your typical macOS malware
FOE Jul 02 Dark Reading
Apple Reverses Age-Old Patch Policy to Keep Up With AI
FOE Jul 02 Krebs on Security
FBI Seizes NetNut Proxy Platform, Popa Botnet
FOE Jul 02 Dark Reading
FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs
FOE Jul 02 The Hacker News
Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices
FOE Jul 02 The Hacker News
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
FOE Jul 02 Dark Reading
Ransomware Thugs Masquerade as Interpol to Entice Small Biz
FOE Jul 02 The Register (Security)
Smooth AI criminal drives 'first' end-to-end agentic ransomware attack
FRIEND Jul 02 EPIC
New Jersey Bans the Sale of Sensitive Data, Creates Data Broker Registry
FOE Jul 02 EFF Deeplinks
LGBT Q&A: How Can I Wipe Online Data That Points To My Queer Identity?
FOE Jul 02 The Register (Security)
Ctrl+Alt+Oops: FortiBleed criminal's logins stitch two gangs together
FOE Jul 02 The Hacker News
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories
FOE Jul 02 Bleeping Computer
Google loses final appeal to overturn €4.1 billion EU fine
FOE Jul 02 EFF Deeplinks
EFF and Allies: X’s FTC Petition to Waive Privacy Violation Order Should be Rejected
FOE Jul 02 SecurityWeek
New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure
FRIEND Jul 02 Professor Messer
Today’s SY0-701 CompTIA Security+ Pop Quiz: Sound it out
FOE Jul 02 The Register (Security)
Microsoft said exploitation was 'less likely' ... but CISA just added SharePoint RCE to KEV list
FOE Jul 02 Bleeping Computer
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
FRIEND Jul 02 SecurityWeek
How to Conduct a Successful Audit of AI-Driven Software Development
FOE Jul 02 The Hacker News
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
FOE Jul 02 The Register (Security)
Pacemaker manufacturer Medtronic warns patients cybercrooks may have swiped health data
FOE Jul 02 SecurityWeek
FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks
FRIEND Jul 02 Dark Reading
Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.
FRIEND Jul 02 Bleeping Computer
Microsoft fixes bug that removed Copilot buttons in Outlook
FRIEND Jul 02 Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: I can do that
FOE Jul 02 CISA Alerts
CubeSpace CW0057 Reaction Wheel
FOE Jul 02 CISA Alerts
ST Engineering iDirect iQ-Series Terminals
FOE Jul 02 CISA Alerts
Gardyn IoT Hub
FOE Jul 02 The Register (Security)
India gives WhatsApp three days to defend username rollout amid security fears
FOE Jul 02 Bleeping Computer
Cisco finally confirms attackers exploiting Unified CM flaw
FOE Jul 02 The Hacker News
Identity Lifecycle Management Wasn't Built for AI Agents
FOE Jul 02 Schneier on Security
Cybersecurity Mission Creep in the US
FOE Jul 02 SecurityWeek
Trump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity Alarm
FOE Jul 02 CSO Online
Argo CD flaw shows why GitOps infrastructure should be treated as tier zero
FOE Jul 02 Bleeping Computer
CISA: Microsoft SharePoint RCE flaw now actively exploited
FOE Jul 02 SecurityWeek
Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability
FRIEND Jul 02 Bleeping Computer
Opera rolls out Paste Protect feature to fight ClickFix attacks
FOE Jul 02 SecurityWeek
‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials
FOE Jul 02 The Register (Security)
Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released
FOE Jul 02 SecurityWeek
CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability
FOE Jul 02 The Hacker News
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
FOE Jul 02 Bleeping Computer
Alleged Scattered Spider hacker extradited to the United States
FOE Jul 02 The Hacker News
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
FOE Jul 02 The Hacker News
New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
FOE Jul 02 The Register (Security)
Hackers shoveled snow for company, were rewarded with network admin access
FOE Jul 02 The Hacker News
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
FOE Jul 02 Risky Business News
Srsly Risky Biz: America Won't Beat the Distillation Ecosystem
FOE Jul 02 Bleeping Computer
Medtronic notifies customers impacted by ShinyHunters data breach
FOE Jul 02 CSO Online
Sandbox bypass flaws in Cursor IDE highlight prompt injection as an RCE vector
FOE Jul 02 Sophos News
Vect and TeamPCP partner for ransomware campaigns
FOE Jul 01 The Register (Security)
EvilTokens device-code phishing kit totally more evil than we all thought
FOE Jul 01 Bleeping Computer
FortiBleed credential-theft campaign linked to Lynx ransomware
FRIEND Jul 01 The Register (Security)
Claude Sonnet 5.0 heads straight down the middle of the road to dodge controversy
FRIEND Jul 01 EPIC
EPIC Commends California For Protecting User Privacy and Speech in Proposed Age Assurance Rules
FOE Jul 01 Bleeping Computer
Kubota says hackers had month-long access to network systems
FOE Jul 01 Dark Reading
Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS
FOE Jul 01 Bleeping Computer
New ChocoPoC malware targets researchers via trojanized PoC exploits
FOE Jul 01 The Register (Security)
Somebody told DeepSeek to build in-browser ransomware and it gleefully complied
FOE Jul 01 Dark Reading
And the Winner in Dominant Malware Delivery? ClickFix
FOE Jul 01 The Hacker News
Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters
FOE Jul 01 The Hacker News
19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges
FRIEND Jul 01 SecurityWeek
Microsoft Adds New Teams Controls to Block Unauthorized AI Bots From Meetings
FOE Jul 01 The Hacker News
SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
FOE Jul 01 Bleeping Computer
DHS confirms hackers breached HSIN info-sharing platform
FOE Jul 01 The Hacker News
VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer
FOE Jul 01 The Register (Security)
Red teamers turned Claude Desktop into a double agent to do their evil bidding
FRIEND Jul 01 Bleeping Computer
Webinar: Why traditional email security is no longer enough
FOE Jul 01 Bleeping Computer
Hackers target Microsoft 365 accounts with 81 million login attempts
FRIEND Jul 01 EPIC
New Jersey Legislature Passes Grocery Surveillance Pricing Ban
FRIEND Jul 01 Dark Reading
When Too Much Security Data Became the Risk
FOE Jul 01 The Hacker News
Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures
FRIEND Jul 01 The Hacker News
Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
FOE Jul 01 Dark Reading
'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat
FOE Jul 01 The Hacker News
Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
FRIEND Jul 01 Bleeping Computer
Turning Indicators into Intelligence in OpenCTI with Criminal IP
FRIEND Jul 01 BrightTALK InfoSec
Strengthening Supply Chain Resilience in a High-Risk Geopolitical Environment
FOE Jul 01 Black Hills Information Security
Finding and Addressing Vulnerable and Outdated Web Application Components
FOE Jul 01 The Hacker News
Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
FRIEND Jul 01 Dark Reading
Safe Events Start With Threat Intel and Digital Security
FOE Jul 01 The Hacker News
AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android
FOE Jul 01 Bleeping Computer
Over 900 Oracle E-Business instances exposed to ongoing attacks
FRIEND Jul 01 Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: Get the wood glue ready
FOE Jul 01 CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog
FOE Jul 01 The Hacker News
2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience
FOE Jul 01 SecurityWeek
Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities
FRIEND Jul 01 SecurityWeek
Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack
FOE Jul 01 Schneier on Security
Papa Johns Surveillance-Based Advertising
FRIEND Jul 01 The Hacker News
Microsoft Accelerates Post-Quantum Cryptography Shift to 2029
FRIEND Jul 01 SecurityWeek
Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors
FOE Jul 01 Bleeping Computer
Amazon fined $2.25M for withholding evidence from fraud victims
FRIEND Jul 01 SecurityWeek
Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari
FRIEND Jul 01 SecurityWeek
Dawnguard Raises $6.3 Million for Security Architecture Automation Platform
FOE Jul 01 SecurityWeek
Massive Password Spray Campaign Targeting Azure CLI
FRIEND Jul 01 Bleeping Computer
Adobe patches seven max severity ColdFusion, Campaign flaws
FOE Jul 01 The Hacker News
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
FOE Jul 01 Risky Business News
Risky Bulletin: Researcher drops giant cache of zero-day exploits
FRIEND Jul 01 CSO Online
Detection engineering: A programmatic approach to identifying cyber threats
FOE Jul 01 The Hacker News
Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls
FOE Jul 01 SecurityWeek
Google Patches 382 Chrome Vulnerabilities
FOE Jul 01 The Hacker News
Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
FOE Jul 01 The Hacker News
Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery
FOE Jul 01 SANS Internet Storm Center
Why Ask Credentials If There Are Secret Codes?, (Wed, Jul 1st)
FOE Jul 01 The Hacker News
Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
FOE Jul 01 Dark Reading
China-Linked Group Targets Southeast Asia Critical Systems
FRIEND Jul 01 EPIC
PRESS RELEASE: EPIC Applauds Passage of the New Jersey Kids Code Act
FRIEND Jul 01 Bleeping Computer
Anthropic to restore Claude Fable access on Wednesday
FOE Jul 01 CISA KEV
CVE-2026-45659: Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
About Methodology Fair Use Privacy Contact RSS

Scanning the threat landscape.