210 posts were published in the last hour
- 21:31 : Claude Mythos Shows AI Can Outpace Human Cryptography Research
- 21:31 : Microsoft Threat Intelligence Portal Retires in August: 4 Checks Before the Cutoff
- 21:31 : Amazon identifies North Korean hacker group behind open-source supply chain attacks
- 20:1 : Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
- 19:31 : SourTrade Malvertising Campaign Secretly Builds Malware in the Browser
- 19:31 : Top 10 Best Security Configuration Assessment Tools in 2026
- 19:31 : Hackers Strike Minnesota Water Utilities, One Plant Briefly Offline
- 19:5 : IT Security News Hourly Summary 2026-07-29 21h : 5 posts
- 19:2 : Closed models refuse to help researcher swat Linux bug
- 19:1 : AI-Generated Phishing No Longer Needs Malware: It Can Steal Your Session Inside the Browser
- 18:31 : Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
- 18:31 : Capital One Open-sources AI Security Tool VulnHunter to Help Developers Identify Exploitable Flaws before Deployment
- 18:31 : Cognyte Sells a Mobile Cell Surveillance Van
- 18:1 : US government bans new foreign-made humanoids, robot dogs, and solar inverters, citing risks to national security
- 18:1 : Why Authentication UX Deserves More Attention on B2B Platforms
- 17:31 : Buying TikTok views or followers? Here’s what you’re really getting
- 17:31 : Java Spring Boot “heapdump” scans, (Mon, Jul 27th)
- 17:31 : Measuring the Tendency of AI Agents to Go Rogue
- 17:31 : Ransomware Groups Increasingly Deploy EDR Kill Techniques
- 17:3 : GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
- 17:3 : Revolut Alleged Data Breach – Hackers Claiming to Access Over 75 Million Users’ Records
- 17:3 : NVIDIA Launches Open Secure AI Alliance to Strengthen AI Security with 36 Industry Partners
- 17:2 : What the Trojan horse gets right (and wrong) about AI security
- 17:2 : CrowdStrike Joins the Open Secure AI Alliance to Advance AI Safety and Security
- 17:2 : EXCLUSIVE: Working Chat Dorking Exposes AI Conversations, Claude, ChatGPT, Grok
- 17:2 : Better security starts with better questions
- 17:2 : Word worm crawls into Copilot, spreads chaos
- 17:2 : TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
- 17:2 : CrashStealer Malware Targets macOS Users by Posing as Apple Crash Reporter
- 17:2 : Hackers Can Hijack Tor Browser Users Through a Single Malicious Web Page
- 17:2 : US Sanctions on VPN Service Briefly Disrupt Telegram’s t.me Link Shortener Due to Compliance Action
- 17:2 : In the Mythos era, security belongs at runtime
- 17:1 : Google to Patch Gemini Flaw That Lets Locked Android 16 Phones Send SMS and WhatsApp Messages Without PIN
- 16:32 : A week in security (July 20 – July 26)
- 16:32 : Russian Intelligence Hackers Phish Signal Backup Keys to Hijack Accounts and Messages
- 16:32 : WP2Shell WordPress Exploit Technical Analysis and Real Attack Data
- 16:31 : macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets
- 16:31 : Microsoft Threat Intelligence Portal Retires August 1: 4 Checks Before the Cutoff
- 16:31 : Critical Ruflo MCP Bridge Flaw Lets Attackers Execute Commands and Hijack AI Agents
- 16:31 : Building Trustworthy Agentic AI: How Security Concerns Have Changed in 2026
- 16:31 : NVIDIA BlueField Vulnerability Enables Code Execution Attacks
- 16:31 : MCBS Healthcare Data Breach Affects 1.26 Million People
- 16:31 : Hijacked Joyfill npm Packages Deploy Worm-Like RAT and Steal Developer Credentials
- 16:5 : IT Security News Hourly Summary 2026-07-29 18h : 9 posts
- 16:2 : Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
- 16:2 : LogoKit Phishing Kit Screenshots Victim Sites in Real Time
- 16:2 : Ernst & Young Notifies Clients Following Third-Party Support Platform Data Breach
- 16:2 : Google goes it alone with a new cybercrime crew taxonomy
- 16:1 : Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
- 15:31 : CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In
- 15:31 : Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
- 15:31 : Iran infrastructure warning, ChatGPT global outage, self-assembling malware
- 15:31 : AI robocalls: Why caller ID is still lying to you
- 15:2 : CVSS 10.0 RufRoot Vulnerability Allowed Attackers to Hijack Ruflo Without Login
- 15:2 : Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
- 15:2 : As data breaches grow costlier, ungoverned AI creates new risks
- 15:2 : Meta AI Bots Drain Publishers With 9 Billion Q2 Requests
- 15:2 : Secure your npm and pip package updates in Amazon Linux
- 15:1 : Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
- 14:31 : Cyber Briefing: 2026.07.29
- 14:31 : ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data
- 14:31 : ISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024, (Mon, Jul 27th)
- 14:31 : Hotel Wi-Fi Hijack, Six Years For A Snapchat Predator, Chicken on the hacking menu globally
- 14:31 : OpenAI explains how its AI agent breached Hugging Face
- 14:31 : JFrog’s 0-days let OpenAI’s models hack Hugging Face
- 14:4 : How to Protect Your AI Agents from Prompt Injection Attacks: An Active Defense Approach
- 14:4 : Sweet Security Brings Autonomous Protection to the AI Enterprise with New Blocking Capabilities
- 14:4 : Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems
- 14:4 : Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution
- 14:4 : US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security
- 14:4 : Frontier Airlines Hit by Third Data Breach
- 14:3 : ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility
- 14:3 : Moonshot AI Claims Kimi K3 Matches OpenAI and Anthropic Models
- 14:3 : Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon
- 14:2 : Huntress Flags Widespread Credential Stuffing Campaign Hitting SonicWall Devices
- 14:2 : Critical VMware vCenter Flaws Let Remote Attackers Bypass Authentication and Execute Code
- 14:2 : CREST Launches AI-Enabled Pentesting Accreditation
- 14:2 : Tengu botnet reboots Linux devices to survive removal
- 14:2 : Critical Ruflo MCP Bridge Flaw Allows Full AI Agent Platform Takeover
- 14:2 : US, Australia Release OT Isolation Guidance
- 14:2 : Stairwell launches Backstory, pioneering agentic investigation for malware blast radius
- 14:1 : IBM: Average Data Breach Cost Hits $5M
- 13:5 : IT Security News Hourly Summary 2026-07-29 15h : 18 posts
- 13:2 : Mate Security Raises $35 Million for Agentic SOC
- 13:2 : macOS ClickFix Attacks Use Fake CAPTCHAs to Deploy Atomic Stealer and Hijack Crypto Wallets
- 13:2 : Houston City College Data Breach Exposes 832k Unique Student Email Addresses
- 13:2 : 120 fake Walmart stores stealing credit cards
- 13:2 : Russia Charges Telegram CEO Pavel Durov With Aiding Terrorism, Issues Arrest Warrant
- 13:2 : CISA adds Arista and Fortinet flaws to KEV catalog
- 13:1 : Fake Recruiters Target Web3 Developers Through Trusted Bitbucket and npm Workflows
- 12:32 : ThreatLocker Raises $190 Million in Series F Funding
- 12:32 : Securing What Matters: Why Cyber Resilience Needs Prioritisation
- 12:32 : JFrog Artifactory Zero-Day Exploited by OpenAI Models to Escape Sandbox
- 12:31 : Mythos Asks the Right Question. It Doesn’t Answer It.
- 12:31 : Android Malware Scanners Are Flagging Legitimate Apps and Missing Threats Without Context
- 12:31 : Managing cyber-physical risk in smart buildings
- 12:31 : 20-Year-Old Vulnerability Enables Takeover of Thousands of Data Centers in Minutes
- 12:31 : Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
- 12:31 : Check Point SmartConsole 0-Day Exploited to Gain Full Administrator Access – PoC Released
- 12:31 : 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
- 12:31 : WhatsApp Adds End-to-End Encryption for Voice and Video Calls
- 12:2 : A Leaked Android RAT Is Powering 170 Servers and Its Successor Is Already Online
- 12:2 : NVIDIA BlueField Flaw Lets VM Users Execute Code via Crafted Messages
- 12:2 : Critical VMware Flaws Allow Attackers to Bypass Authentication and Gain Access to the System
- 12:2 : Critical VM Escape Vulnerability Patched in VMware ESXi
- 12:2 : VulnGym Uses AI-Trained APT Attackers to Stress-Test Enterprise Patching Strategies
- 12:2 : Threat Actor Claims Revolut Data Breach Exposes Financial Records of 75 Million Users
- 12:2 : CISA Releases Checklist for Critical Infrastructure Organizations to Isolate Vital Systems
- 12:2 : Russian Intelligence Hackers Target Signal Backup Recovery Keys in Account Takeover Attacks
- 12:1 : AsyncAPI Malware Contains Modules to Steal GitHub, npm, Cloud and AI API Credentials
- 11:31 : Contrast CVE Shield aims to protect applications while security teams deploy patches
- 11:31 : Long-Lived Vulnerability in Microsoft Secure Boot
- 11:31 : OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach
- 11:31 : Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
- 11:31 : CISA Urges Critical Infrastructure Operators to Isolate Vital OT Systems During Cyberattacks
- 11:31 : The Average Cost of a Data Breach Rises to $5 Million
- 11:31 : MIND AI DLP Agents automate DLP classification, investigations and remediation
- 11:2 : US, Australia Release OT Isolation Guidance for Critical Infrastructure
- 11:2 : Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
- 11:2 : Emerging drug trafficking corridor from Western to Eastern Europe disrupted
- 11:2 : Falcon Secure Access Sets the Standard for Zero Trust Browser Security
- 11:2 : We found 120 fake Walmart stores trying to steal your credit card
- 11:2 : Why AI Governance Without Guardrails Is Theater
- 11:2 : Houston City College Data Breach Impacts 832,000 Students and Alumni
- 11:2 : PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
- 11:1 : Joyfill npm Supply-Chain Attack Deploys RAT and Developer Credential Stealer
- 11:1 : CrowdStrike Uncovers New Prompt Injection Techniques
- 10:32 : Cloudflare reveals what’s behind major internet outages
- 10:32 : 28 arrests in international strike against child sexual exploitation
- 10:32 : Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows
- 10:31 : Beyond the Model: Harnessing Frontier AI for Stronger Cyber Defense
- 10:31 : OpenAI’s Rogue AI Ventured Beyond Hugging Face
- 10:31 : CrowdStrike Falcon Platform Helps Meet U.S. Government Mandates for CISA BOD-26-04
- 10:31 : French-Spanish operation targets hazardous waste trafficking network: four arrested
- 10:31 : July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
- 10:31 : When violence shapes identities in a larger pool of perpetrators: new Europol terrorism report
- 10:31 : The Oracle of Delphi Will Steal Your Credentials
- 10:31 : Fact Check: Clarifying claims about Europol’s operational processing environments
- 10:31 : AIDR: How CrowdStrike Is Defining the Next Era of Cybersecurity
- 10:5 : IT Security News Hourly Summary 2026-07-29 12h : 25 posts
- 10:2 : Migrant smuggling network using rental cars dismantled across the Balkans
- 10:2 : Fake Web3 Job Interview Software Delivers Infostealer to Steal Crypto Wallets and Passwords
- 10:2 : Five arrests for smuggling migrants across the Bulgarian-Serbian green border
- 10:2 : Keep Your Tech Flame Alive: Trailblazer Rachel Bayley
- 10:2 : Europol-led action against nihilistic violent extremist network “The Com”
- 10:2 : Threats Making WAVs – Incident Response to a Cryptomining Attack
- 10:2 : Europol and Frontex strengthen cooperation with new Working Arrangement
- 10:2 : The Nansh0u Campaign – Hackers Arsenal Grows Stronger
- 10:1 : Europol supports operation against amphetamine producers
- 9:32 : Spur Raises $200 Million for IP Intelligence Platform
- 9:32 : Critical WordPress Plugin Backdoor Exposes 20,000 Sites to Full Administrator Takeover
- 9:32 : ICE’s New Detention Center Contracts Declare State Laws ‘Shall Not Apply’
- 9:32 : Accuris uses AI to improve BOM decisions and supply chain resilience
- 9:32 : VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims
- 9:32 : Researchers Warn of AI-Enhanced Phone Fraud Ecosystem
- 9:32 : 22-Year-Old IPMI Flaw Exposes 24,000 Servers to Offline Password Cracking
- 9:32 : China’s Moonshot AI Seeks Nvidia Blackwell Chips
- 9:32 : New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
- 9:31 : Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware
- 9:31 : OpenAI’s Rogue AI Agent Breached Second Company, Report Says
- 9:31 : Rogue OpenAI Agent Also Compromised Second Firm
- 9:31 : Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
- 9:31 : Apple Surpasses $5tn Valuation Amid AI Plunge
- 9:31 : Check Point SmartConsole Zero-Day Lets Unauthenticated Attackers Gain Full Admin Access
- 9:31 : Ofgem Proposes Stiffer Rules For Data Centre Projects
- 9:3 : JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
- 9:2 : NCSC Publishes Guidance to Aid Incident Response and Recovery
- 9:2 : Bank of Baroda Data Breach – Hackers Gained Access Via Employee Email Account
- 9:2 : FortiGate 1200G brings FortiSASE Outpost to customer-controlled environments
- 9:2 : Critical Gitea Vulnerability Allows Attackers to Execute Malicious Code Remotely
- 9:2 : Stolen Meta and Google ad accounts are worth more than the money they hold
- 9:1 : WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2
- 8:31 : WhatsApp brings end-to-end encrypted voice and video calls to the web
- 8:31 : Root Evidence puts real-world evidence at the center of vulnerability prioritization
- 8:31 : Torq makes AI SOC investigations continuously self-learning
- 8:31 : Flying Eagle RAT Abuses Android Accessibility Services for Keylogging, Screen Capture and Gesture Injection
- 8:31 : 1Password targets standing privileges with new access management capabilities
- 8:2 : Google Australia Customers Now Benefit From Imperva Cloud-Native WAAP Security
- 8:2 : Tines introduces AI-native platform for secure enterprise workflow automation
- 8:2 : Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
- 8:2 : Mend.io enhances application security with AI runtime protection and faster zero-day response
- 8:2 : Apple Patches Everything (July 2026), (Wed, Jul 29th)
- 8:2 : Realm Security adds Detection Integrity and Data Haven Search to cut SIEM costs
- 8:2 : Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
- 8:2 : Abnormal AI extends behavioral security to identities, AI systems, and insider threats
- 7:31 : ZeroFox unveils HNTR and Executive Protection for AI-driven threat detection
- 7:31 : JFrog Patches Artifactory Zero-Days After OpenAI Models Escape Sandbox
- 7:31 : Leaky BMCs, Claude finds encryption flaws, Google’s new names
- 7:31 : Sensitive, Bizarre Anthropic Claude Chats Exposed Online
- 7:31 : Infoblox enters EASM market with attack surface and supply chain risk tools
- 7:31 : Bank of Baroda Confirms Data Breach After Employee Email Account Compromised
- 7:31 : Reco enhances AI Runtime with browser-based AI security and automated remediation
- 7:5 : IT Security News Hourly Summary 2026-07-29 09h : 6 posts
- 7:2 : OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
- 6:31 : Hackers Are Hiding Commands in Emails to Trick the AI Systems Protecting You
- 6:31 : An AI agent can pass every safety check and still leak secrets
- 6:31 : Apple Releases Security Updates Patching Nearly 200 Vulnerabilities Across macOS, iOS, iPadOS, and Safari
- 6:31 : ShinyHunters Claims Ernst & Young Hack
- 6:31 : Malicious npm Packages Deploy Cross-Platform RAT Targeting Alibaba Developers
- 6:2 : Attackers Split RAT Components Across npm Packages to Evade Isolated Code Reviews
- 6:2 : The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced
- 5:31 : Cybercriminals Use Adversarial Prompt Injection to Evade AI-Powered Security Tools
- 5:31 : Specter: Open-source NFC reader bug sweep for Flipper Zero
- 5:2 : Your AI agents can reach data no one approved
- 5:1 : OpenAI Open-Sources Codex Security CLI to Find, Validate, and Fix Code Vulnerabilities
- 4:31 : Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
- 4:31 : Autonomous AI Agent Escapes Sandbox and Breaches Hugging Face Production Systems
- 4:31 : Android malware detection collapses when the context stage comes out
- 4:31 : Claude AI Autonomously Discovers Cryptographic Weaknesses That Escaped Expert Review
- 4:5 : IT Security News Hourly Summary 2026-07-29 06h : 3 posts