Brown Health Medical Group-MA breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. Brown…
Category: EN
5 Best AI Detection & Response Platforms for 2026
Compare AI detection & response platforms for 2026, including Dash, Lakera, Operant AI, HiddenLayer and Prisma AIRS, for runtime threat protection and…
Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
More than 50 offending image and video ads were published across Facebook, Instagram, Messenger, or Threads, according to Meta’s ad library data. Some ran…
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP…
Microsoft Awards Record $20 Million to 562 Researchers in Biggest Bug Bounty Year
Microsoft has awarded more than $20 million to 562 security researchers through its bug bounty program, marking the largest annual payout in the company’s…
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer’s computer. Paperclip is an open-source control…
Cybersecurity Skills Gap: More Than Just a Workforce Challenge
Learn why the cyber skills gap is a business risk according to the Fortinet 2026 Cybersecurity Skills Gap Report findings.
SMOKE#SCREEN Campaign Abuses ScreenConnect RMM and Cloudflare Tunnels to Hijack Windows and macOS Systems
SMOKE#SCREEN is a campaign that turns ordinary software updates and business files into a doorway for remote control. Victims who run the files can…
Fake Open VSX Extensions Harvest Private Repo and CI Data
77 counterfeit Open VSX extensions beaconed to one domain, 19 harvesting git and CI identity
Top product launches at Black Hat USA 2026
Black Hat USA 2026 is underway in Las Vegas, and vendors are using the moment to unveil what they hope will define the next year of defense. Here are the…
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes…
White House walks tightrope on securing AI without stifling tech innovation
National Cyber Director Sean Cairncross said the administration wants to work collaboratively with the private sector.
RansomHouse Claims Responsibility for Cyberattack Disrupting Nichirei Operations in Japan
Japanese frozen-food and logistics company Nichirei is currently dealing with an unknown cyberattack that caused the disruption of the firm’s nationwide…
U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited…
Black Hat USA 2026 – Summary of Vendor Announcements (Part 3)
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root
OVSwrap is a 13-year-old Linux kernel flaw that lets local users gain root privileges on most distributions using Open vSwitch. Security researcher Asim…
“I’m Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails
Cisco Talos found hackers using simple authorization claims to bypass AI guardrails, build DDoS attack tools, steal credentials and access live camera…
Cyber Briefing: 2026.08.05
Security risks are shifting from unpatched infrastructure and massive cloud data exposures toward architectural vulnerabilities and governance
Stolen Greatness Tokens Provide Microsoft 365 Access More Than Two Weeks After Phishing
Stolen Greatness authentication tokens are providing sustained, MFA‑approved access to victim Microsoft 365 tenants for more than two weeks after the…
77 Evil Twin Open VSX Extensions Exfiltrate Private Git Repository and CI Data
A wave of counterfeit Open VSX extensions has exposed how easily a familiar developer tool can become a data collection channel. Seventy-seven packages…
