
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. […]

CSS was once just about design. Now researchers warn it’s powerful enough to exfiltrate data from webmail — and some vendors aren’t prepared.

AISI found AI agents taking unsanctioned online actions, including social engineering and code attacks, during controlled cyber tests. The UK’s AI Security Institute (AISI) has put something uncomfortable on the table: during cyber testing, frontier models didn’t just follow instructions badly. In some runs, they crossed into real-world actions, touched real people and organisations, and…
Small enough to slip into a backpack, Lenovo’s Yoga Mini Gen 11 is a solid work PC with unique tricks up its sleeve.

Until recently, it was common for companies and organizations to engage in “tokenmaxxing” — that is, maximizing their use of AI. But with AI costs going up, companies are now looking to save money, a trend underscored by a recent Microsoft decision to limit AI use by its employees. “As we ramp up our use…

An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker runs code on the host. Bonita BPM handles loan approvals, insurance claims, and employee onboarding for banks, insurers, and government agencies, and its internal…

A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake…

OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a…
When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In the keyv/cacheable compromise that has been unfolding since yesterday, it is the one…
Turtlebox returns with the Cub, proving that its smaller speakers can be just as durable and powerful as its larger ones.
T-Mobile customers affected by the outage in July have been requesting credit. Though $10 is standard, the more persistent you are, the more you may be able to get.
Imagine preparing for your biggest sales event of the year, and you want to ensure your customer identity management service can handle the elevated traffic for carrying out application activities. For security teams, business leaders, and technologists managing identity infrastructure at scale, this scenario has been all too familiar. Whether you’re a CISO evaluating security…
The hidden diagnostic file breaks down all the logging your Pixel, Samsung, or even Motorola does daily. Here’s what you can learn from it.

The memory crisis is getting worse for Apple, which is struggling to get enough memory chips together for its upcoming iPhone 18 Pro series smartphones. That’s according to tech journalist Tim Culpan. As he details it, Apple and its assembly partners are still attempting to secure sufficient quantities of memory, and though they’re confident they can meet…

Trustifi is expanding beyond email security with a new platform designed to help managed service providers detect threats, enforce data-loss prevention policies and investigate incidents across Microsoft Teams, OneDrive and SharePoint. The company’s new Collaboration Shield platform applies Trustifi’s security and compliance capabilities to Microsoft 365 collaboration workloads, where employees increasingly exchange sensitive files and…

Cynomi has announced a strategic partnership with SPECTRA, the MSP certification and cyber resilience warranty platform. The partnership gives Cynomi partners a direct, in-platform path to SPECTRA Certification, allowing them to validate the security services they deliver, offer warranty-backed protection to clients, and potentially reduce cyber insurance costs for both MSPs and their customers. Demonstrating…

Brown Health Medical Group-MA breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. Brown Health Medical Group-MA data breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. The healthcare group identified a data security breach involving a legacy file server on…
Apple restored Telegram to its App Store after a brief removal due to reported child sexual abuse material.
Three other longtime Google scientists will join Jeff Dean to launch Discovery Loop, which will apply automated AI research to drug design and other challenges.
One method is easier, but the other gets you faster, more reliable performance.
The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. […]
Based on information from cyberscoop, the Senate Committee on Commerce, Science and Transportation is preparing to debate a series of new bills aimed at enhancing online privacy, protecting children, and regulating artificial intelligence.
AI-driven cybercrime now constitutes 55% of all reported digital crime in Africa, according to a new report from Interpol.
Nextgov reports that a new House investigation reveals that three Chinese state-owned telecommunications providers have maintained equipment, data-center space, and network connections in the United States, years after federal regulators sought to remove them on national security grounds.
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access to Anthropic’s large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. “Advertisements for Poison Claude
77 counterfeit Open VSX extensions beaconed to one domain, 19 harvesting git and CI identity
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-9198 (CVSS score of 9.8) IBM Langflow Code Injection Vulnerability CVE-2026-18556 (CVSS score of 8.2) N-able N-central Authentication…
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer’s computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it. A third flaw could expose sensitive data and control-plane details through application…
Here’s how AI SBOMs can help team make supply chain risk more manageable.

Black Hat USA 2026 is underway in Las Vegas, and vendors are using the moment to unveil what they hope will define the next year of defense. Here are the announcements drawing the most attention on the ground, and why they matter for teams weighing new budgets. BlackCloak extends deepfake protection to the executive’s trusted…
Google has locked hundreds of Blogger websites after a false positive claimed they violated its “Malware and Similar Malicious Content” policy, with some sites deleted from the platform. […]
Cisco Talos found hackers using simple authorization claims to bypass AI guardrails, build DDoS attack tools, steal credentials and access live camera services.

Stellar Cyber, the full-cycle AI-native security operations platform company, today released results from an independent study of 124 days of customer trials of its Agentic Auto Triage capability. The independent study based on customer trials evaluated 138,475 real security alerts and reached the same verdict as human analysts 99.7% of the time. The findings, drawn…
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam’s console that hands over a managed agent’s credentials, rated 9.5 A cross-tenant flaw in HashiCorp’s MCP server that lets one user’s Terraform token be reused…
OVSwrap is a 13-year-old Linux kernel flaw that lets local users gain root privileges on most distributions using Open vSwitch. Security researcher Asim Manizada disclosed OVSwrap (CVE-2026-64531, CVSS score of 7.8), a local privilege escalation vulnerability in the Linux kernel’s Open vSwitch datapath that lets an ordinary user become root on a wide range of…

AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection offers a more durable defense than relying on domains, signatures, and other known-bad indicators. […]
I fact-checked the internet’s favorite battery tips, and most of them are horribly outdated.
LAS VEGAS, Aug. 5, 2026, CyberNewswire – Boards of directors believe they understand their company’s security posture and what it means for the business. The security leaders presenting to them are far less sure. Only 12.5% of security leaders are very confident their board walks away understanding the true state of the program, and 55%…
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm package “bianira-ui” and “fluid-type-ui,” has been codenamed NullReceiver by
I create Windows 11 system restore points before most major changes – and you should, too. Here’s why.

Tenable has announced enhanced AI security capabilities within the Tenable One Exposure Management Platform. Tenable One AI Exposure now delivers expanded platform coverage with support for Google Gemini, extending its coverage across major LLMs: Google Gemini, Anthropic Claude, OpenAI ChatGPT Enterprise and Microsoft Copilot. The release also extends discovery to all major Model Context Protocol…
Las Vegas, United States, 5th August 2026, CyberNewswire

Registration is now open for the PCI Security Standards Council’s 2026 Community Meetings! Join payments industry professionals from around the world for inspiring keynotes, valuable networking opportunities, expert-led sessions, hands-on workshops, an expansive vendor showcase, and a special celebration marking 20 years of PCI SSC.

ArmorCode has announced a major expansion of its Agentic Control Plane. Four new Anya AI agents help security teams analyze cloud risks, assess vulnerability exploitability, identify mitigation strategies, and coordinate patch orchestration. It also unveiled new Context Risk Graph capabilities for expanded attack path analysis, network reachability and patch management. These enhancements help security teams…
I tested today’s leading AI voice tools to find which delivers the best accuracy, privacy, corrections, and everyday productivity without slowing down real work.

TeamPCP, the threat actor behind an unrelenting flurry of attacks on open-source software this year, has been active much longer than previously thought, according to research Oligo Security shared exclusively with CyberScoop. The threat actor, which gained notoriety and has captivated threat hunters as it compromised and injected malicious code into more than 1,000 software…

Tuskira has launched its Agentic Control Plane for Exposure Management, a new capability within the Tuskira platform that governs AI-discovered vulnerabilities from scan to verified closure. The capability extends Tuskira’s existing zero-day and exposure-response capabilities to frontier-model scanning. Tuskira applies enterprise policy to AI and legacy scanner workflows, maps findings to the deployed environment, determines…
Discover how Tenable Hexa AI closes the gap between exposure management and endpoint patching using intent-driven routines, smart guardrails, and human approval. Key takeaways The problem: A slow handoff between security workflows creates a days-long remediation gap. The solution: Tenable Hexa AI bridges this gap using intent-driven Routines that automate scoping, deployment, and verification across…

Lumu has announced the release of Lumu Threat Observatory as part of Maltiverse, its threat intelligence solution. Lumu Threat Observatory is Maltiverse’s live, personalized threat-intelligence experience, providing organizations with a complete, live view of the active threats targeting their specific sector, helping them spot malicious adversaries early, prioritize vulnerabilities, and automatically block them. While threat…
Windows is in decline, and both Macs and Linux are gaining ground at its expense.

Africa’s growing digital economy is exposing governments, businesses and internet users to a rising wave of cybercrime. The continent recorded more than 1.1 billion mobile subscriptions and over $1.1 trillion in digital transactions in 2025, while more than 570 million people relied on the internet for banking, government services, healthcare and education. The post INTERPOL…

“During a routine cyber evaluation, AI agents took sustained, unsanctioned action directed at real people and organisations,” UK’s AI Security Institute (AISI) disclosed on Tuesday. The agents’ actions included an attempted supply-chain attack that saw them create malicious pull requests and try to socially engineer an open-source maintainer into approving the malicious code (they refused).…

Security researchers are warning against trust assumptions in AI security with newly detailed flaws affecting the open-source AI agent platform Paperclip that could be chained into remote code execution (RCE), data exposure, and developer-machine compromise. An Oasis Security research shared with CSO ahead of its publication on Wednesday disclosed details of three recent vulnerabilities affecting…

A memory corruption flaw in the Linux kernel’s Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds. The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed…
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft’s real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure,…

OpenAI’s GPT-5.6 Sol and Anthropic’s Mythos 5 have been implicated in another series of AI security incidents after the models created fake online identities, targeted real people, and attempted to manipulate developers into approving malicious code during controlled cyber evaluations, according to the UK AI Security Institute. “On 28th July 2026, AISI’s Security Team detected unusual…

An automated system called NOVA read the source code of 3,915 open-source projects over two months and came back with 14,090 vulnerabilities, each one confirmed through the system’s validation pipeline. Vulnerability researchers at Palo Alto Networks’ Unit 42 built the system and checked its output against the public record afterward. Only 85 findings matched anything…

Passkeys were supposed to make stolen passwords a thing of the past. No password to phish, no secret to reuse, and no string of characters sitting in a database waiting to be leaked. Over time, it’s thought that passkeys will replace passwords entirely. But what happens when malware steals the master key? Researchers have found…

An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1. The file-read flaw is tracked as CVE-2026-59774, rated Critical with…

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability. We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the…
It’s come to this. A cyberattack carried out by a machine. Worse, a machine that picked its own victim. Whether that counts as agency is where the experts below part company. Related: Huggy Face break-in explained Hugging Face disclosed July 16 that intruders had moved through its production infrastructure over more than four days, harvesting…
Create the ultimate movie theater experience at home with 98-inch TVs from Hisense, Samsung, and more.

I was mapping the command-and-control infrastructure behind a state-linked intrusion set when the query came back and effectively ended the exercise I thought I was running. The malware resolved its C2 address by reading a smart contract on a public blockchain. Public reporting described one contract. Working from the chain rather than the sample, I…

Losing access to your Google account might just be the epitome of a modern-day nightmare. Especially if you’re using Android and even more so if you’re invested in lots of different Google services on top of that, the amount of access and info connected to that one single sign-in is just staggering. Think about it:…

TP-Link prints the serial number of an Omada router on its packaging and on a label attached to the device. Those numbers run in sequence, and feeding a guessed one to the Omada cloud service returns the matching device’s MAC address and model. Serials beginning 22460J500 appear to be ER605 routers, and serials beginning 224608100…

A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The “evil twin” extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have…

Your phone is full again, and the warning appears at exactly the wrong moment. Suddenly you can’t update apps, record a video, or save another photo. The cause is rarely one giant file. Storage disappears in a steady drizzle of leftovers: temporary files an app creates and forgets, caches that grow in the background,…

Comparisons of LangChain, CrewAI and AutoGen are easy to find — dozens of guides this year cover the same ground: developer experience, ecosystem maturity, how easy it is to wire up multi-agent workflows. None of them ask the question I actually care about: does the framework you pick change how easily your agent gets compromised?…

Like seemingly everything else these days, artificial intelligence will re-shape the way voters gather information on candidates running in the 2026 midterm elections. In some ways, this is already the reality. Voters are increasingly turning to AI chatbots for information instead of Google. Political campaigns are deploying deepfakes of their opponents. And AI systems have…

A phishing campaign impersonating Bank of America (BoA) is underway, trying to trick Windows users into installing ScreenConnect remote access software and then making it difficult to uninstall it. Different traps for Mac and Windows users By claiming the recipient must take specific actions “to avoid account restrictions,” the email, sent from onlinebanking@ealerts[.]bkofamerica[.]com, tries to…

Recent high-profile rogue agent incidents involving OpenAI and Anthropic underscore the fact that organizations can’t put blind trust in their AI guardrails. Moreover, they must able to turn off agents quickly when they deviate from intended behavior — before they can do potentially catastrophic damage. For legal services company Purpose Legal, that includes incorporating a…
ChongLuaDao protects over 200 million users from cybercrime, having detected more than 1.4 million malicious websites since 2020. Rapid processing of community reports is essential to their operations. In our recent conversation, ChongLuaDao co-founder Hieu Ngo told us how ANY.RUN plays an integral role in the project’s infrastructure, helping it power thousands of safety checks…