Astaroth operators have expanded their Brazilian banking malware operations by weaponizing a new WhatsApp Web spambot module that turns infected hosts…
NCSC Publishes Guidance to Aid Incident Response and Recovery
The National Cyber Security Centre has released a detailed framework to assist with incident response and recovery
ShutterGap Exposes Millions of Misconfigured AWS Resources to Attackers
A cloud-security blind spot known as Cloud ShutterGap, which involves millions of AWS resources being briefly exposed to the public before being removed,…
Over-the-Air Vehicle Updates Raise Cybersecurity and National Security Concerns
Modern vehicles are being transformed by the adoption of over-the-air (OTA) technology. However, cybersecurity experts warn that the same technology can…
CosmosEscape Vulnerability Enables Full Takeover of Azure Cosmos DB Databases
A critical vulnerability chain in Azure Cosmos DB, named CosmosEscape, allowed attackers to gain full read and write access to every Cosmos DB database,…
Aviation cyber risk sits on the ground, the blindness sits in the air
In this interview with Help Net Security, Eliran Almong, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays…
Anthropic Claude AI Accidentally hacked 3 Companies During Routine Security Test
HOC Shorts | Summary What Happened: Anthropic revealed that three of its Claude AI models accessed and interacted…
CISA Urges Water Utilities to Remove Publicly Exposed PLCs From the Internet
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert to the Water and Wastewater Systems (WWS) Sector due to a…
OctLurk and SilkLurk Backdoors Target Central Asian Governments in Cyberespionage Campaign
OctLurk and SilkLurk are highly customized, memory‑resident backdoors used in an ongoing cyberespionage campaign against government and critical‑sector…
Companies push AI, sysadmins keep it on a short leash
In 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response…
Analog Devices Confirms Cyberattack After Hackers Exfiltrate Files From Company Systems
Analog Devices, Inc. has confirmed that unauthorized actors gained access to certain company systems and exfiltrated files. The semiconductor manufacturer…
Anthropic Confirms Claude AI Models Hacked 3 Organizations During Cybersecurity Evaluations
Anthropic has disclosed that three Claude AI models gained unauthorized access to the production systems of three real-world organizations during…
AI agents are changing where cybersecurity seed funding lands
Founders pitching a cybersecurity seed round this summer are joining a line that keeps getting longer. Product Hunt launches hit their highest level since…
New infosec products of the week: July 31, 2026
Here’s a look at the most interesting products from the past week, featuring releases from BlackCloak, Contrast Security, Dropzone AI, PortSwigger, Realm…
Google Australia Customers Now Benefit From Imperva Cloud-Native WAAP Security
Many Australian businesses have moved their applications and data to cloud-native architectures for agility, scalability, and sovereignty. However, this…
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent…
Anthropic’s Claude escaped test sandbox to attack three organizations
Wrote and published malware during tests, which is apparently OK because leaky test environments were the real problem
Cryptominer Abuses Linux PAM to Hide From SOC Analysts
Cryptomining crew abandoned root to impersonate low-privileged Linux users and evade SOC alerts
Apple Patches Everything (July 2026), (Wed, Jul 29th)
I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets…
OpenAI’s rogue agent hit more victims, attackers hit 30 Minnesota water systems, Russian crew delivers weaponized e-mails in Exchange
OpenAI ‘Rogue Agent’ Fallout, Minnesota Water Systems Hit, Exchange OWA Zero-Click Mailbox Takeover David Shipley covers multiple security stories: the…
AiTM Phishing Becomes Top Initial Access Threat to Law Firms
AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats
Anthropic Says Claude Hacked 3 Organizations During Cybersecurity Tests
In a review triggered by OpenAI’s Hugging Face incident, Anthropic discovered three of its AI models had breached real organizations during third-party…
ISC Stormcast For Friday, July 31st, 2026 https://isc.sans.edu/podcastdetail/10032, (Fri, Jul 31st)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Friday, July 31st, 2026 https://isc.sans.edu/podcastdetail/10032,…
AI Escaped a Sandbox. That is Not What Should Worry You
What OpenAI’s and Anthropic’s testing incidents really teach defenders In the past two weeks, two of the world’s leading AI labs have disclosed the same…