210 posts were published in the last hour
- 21:31 : Friday Squid Blogging: Squid Helps Discover New Marine Species
- 21:31 : Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
- 21:31 : Headteacher had the most guessable username-password combo you could imagine
- 21:1 : 2026-7-31: SmartApeSG ClickFix campaign pushes unidentified RAT
- 21:1 : Excuses like ‘AI did it’ don’t exist in the eyes of the law
- 20:31 : Anthropic Says Claude Models Hacked 3 Organizations During Cyber Tests
- 20:31 : eSecurityPlanet Podcast: Semperis Global Field CTO Marty Momdjian
- 20:31 : Wordfence Bug Bounty Program Monthly Report – April 2026
- 20:2 : CyberStrike – AI-Powered Security Platform for Automated Penetration Testing
- 20:2 : HIPAA Security Rule on AWS – Technical Safeguards Implementation and Readiness Guidance
- 20:2 : Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
- 20:2 : FTC Sues Hims & Hers Over Alleged Privacy Violations, Subscription Practices
- 20:2 : Keycloak Vulnerability Exposes User Names and Email Addresses Across Admin Boundaries
- 20:2 : Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical
- 20:1 : Your Incident Response Plan Has a Dependency You Never Approved
- 19:31 : How Federal Agencies Can Turn Year-End Funding Into Long-Term Cyber Capability
- 19:31 : Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
- 19:5 : IT Security News Hourly Summary 2026-07-31 21h : 3 posts
- 18:31 : Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th)
- 18:31 : IBM: AI-Enabled Data Breaches Cost Organizations $6 Million on Average
- 18:31 : ISC Stormcast For Thursday, July 30th, 2026 https://isc.sans.edu/podcastdetail/10030, (Thu, Jul 30th)
- 18:2 : HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
- 18:2 : Apple accused of letting fake crypto app steal $1.8 million
- 18:2 : The Hidden Security Problem Holding Enterprise AI Back
- 18:2 : Inside Astaroth’s New Spambot Component
- 18:2 : ShinyHunters Claims Brinks Home Salesforce Data Theft
- 18:2 : LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach
- 18:2 : MQTT and Friends – Introducing BrokerLine
- 18:2 : Apple Sued After Alleged Fake Crypto Wallet App Cost Users $1.8 Million
- 18:2 : Falcon Platform IOAs Arrive in Falcon Next-Gen SIEM to Identify New Threats
- 17:32 : Vulnerability management needs an update for the AI era
- 17:32 : Revolut Data Breach? Hackers Claim 75 Million User Records
- 17:31 : From Benchmark to Breach: Inside the First End-to-End Autonomous Cyberattack
- 17:31 : Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
- 17:31 : Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the Cloud
- 17:31 : What to know about deepfake phishing simulation software
- 17:31 : Minnesota Water Utilities Hit by Coordinated Cyberattack
- 17:2 : How Status Labs Helps Brands Get Cited in ChatGPT: The Data Behind AI Search Visibility
- 17:2 : US authorities see ‘significant escalation’ in attacks on water system devices
- 17:2 : Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave
- 17:2 : Microsoft Threat Intelligence Portal Retires in August: 4 Checks Before the Cutoff
- 17:2 : Beyond Deadlines: CMMC As A Continuous Enterprise Risk Governance Challenge
- 17:2 : Amazon identifies North Korean hacker group behind open-source supply chain attacks
- 17:1 : Data Loss Risks During Microsoft 365 Migration and Ways to Prevent Them
- 16:32 : US government bans new foreign-made humanoids, robot dogs, and solar inverters, citing risks to national security
- 16:32 : Does a VPN Drain Battery? How to Save Device Power While Staying Safe
- 16:32 : The most famous brand in physical security got pwned by ShinyHunters
- 16:31 : Why Authentication UX Deserves More Attention on B2B Platforms
- 16:31 : Capital One Open-sources AI Security Tool VulnHunter to Help Developers Identify Exploitable Flaws before Deployment
- 16:31 : Fake Fortnite rewards are stealing players’ accounts
- 16:31 : Measuring the Tendency of AI Agents to Go Rogue
- 16:31 : Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
- 16:31 : Closed models refuse to help researcher swat Linux bug
- 16:31 : Buying TikTok views or followers? Here’s what you’re really getting
- 16:5 : IT Security News Hourly Summary 2026-07-31 18h : 31 posts
- 16:3 : Intel 471 Warns of Expanding Software Supply Chain Attacks
- 16:3 : In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
- 16:3 : NVIDIA Launches Open Secure AI Alliance to Strengthen AI Security with 36 Industry Partners
- 16:3 : Word worm crawls into Copilot, spreads chaos
- 16:3 : AI Attacks: Have Manufacturers Lost Control?
- 16:2 : Anthropic says human error let Claude AI models escape test environment and hack third parties
- 16:2 : Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
- 16:2 : CrowdStrike Joins the Open Secure AI Alliance to Advance AI Safety and Security
- 16:2 : CrashStealer Malware Targets macOS Users by Posing as Apple Crash Reporter
- 16:2 : Better security starts with better questions
- 16:2 : Google to Patch Gemini Flaw That Lets Locked Android 16 Phones Send SMS and WhatsApp Messages Without PIN
- 16:2 : WP2Shell WordPress Exploit Technical Analysis and Real Attack Data
- 16:1 : US Sanctions on VPN Service Briefly Disrupt Telegram’s t.me Link Shortener Due to Compliance Action
- 15:32 : Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers
- 15:32 : Shareware vs. Freeware: Key Differences Explained
- 15:32 : Building Trustworthy Agentic AI: How Security Concerns Have Changed in 2026
- 15:32 : Indian Banks Increase Cybersecurity Investments to Counter AI-Powered Cyber Threats
- 15:32 : Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
- 15:32 : LogoKit Phishing Kit Screenshots Victim Sites in Real Time
- 15:32 : Critical SolarWinds Flaw Lets Attackers Bypass Web Help Desk SAML Login
- 15:32 : Anthropic and OpenAI are competing to see whose agents can go rogue harder
- 15:32 : MCBS Healthcare Data Breach Affects 1.26 Million People
- 15:32 : CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In
- 15:32 : Fitness Trackers Can Expose Your Health Data, EFF Warns
- 15:31 : SSH Bot Profiles Linux CPU, GPU and RAM Before Deploying Cryptocurrency Miner
- 15:31 : Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
- 15:31 : DeepSeek-Powered Hermes Agent Launches Autonomous Cyberattacks Against Exposed Servers
- 15:31 : Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
- 15:31 : ShutterGap Exposes Millions of AWS Resources Between Cloud Security Scans
- 15:31 : Ernst & Young Notifies Clients Following Third-Party Support Platform Data Breach
- 15:31 : CMMC Phase II Is Paused, But Contractors’ Data-Security Obligations Are Not
- 15:3 : Cyber Briefing: 2026.07.29
- 15:3 : Enterprise ERP AI Adoption Outpaces Security Readiness
- 15:3 : As data breaches grow costlier, ungoverned AI creates new risks
- 15:3 : Critical Flaw Allowed to Azure Cosmos DB Pwnage
- 15:3 : Secure your npm and pip package updates in Amazon Linux
- 15:2 : FBI And Allies Warn of North Korean IT Workers Using Stolen Identities
- 15:2 : Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
- 15:2 : AI robocalls: Why caller ID is still lying to you
- 15:2 : Google AI Supercharges Chrome Security, Fixing 1,072 Bugs
- 15:2 : North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials
- 15:2 : Meta AI Bots Drain Publishers With 9 Billion Q2 Requests
- 15:2 : Google Uses AI Agents to Find and Fix 1,072 Chrome Security Vulnerabilities
- 15:2 : AI-Speed Attacks and Critical Flaws Compress Defenders’ Response Window this Week of July 2026
- 15:2 : BlackTech APT Deploys BlueShell Linux Backdoor Against Japanese Organizations
- 15:1 : Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
- 15:1 : Critical JetBrains Flaw Allows Attackers to Execute Malicious Code Remotely – Update Now
- 14:32 : Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems
- 14:32 : Sweet Security Brings Autonomous Protection to the AI Enterprise with New Blocking Capabilities
- 14:32 : Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
- 14:32 : Operationalizing Offensive AI: An Open Framework for Modern Security
- 14:31 : OpenAI explains how its AI agent breached Hugging Face
- 14:31 : Securing Loop Engineering: Six Trust Boundaries for Autonomous Agents
- 14:31 : Anthropic Says Claude Hacked Into 3 Organizations During Cybersecurity Tests
- 14:31 : Retrieval Augmented Generation With Spring AI 2.0, Claude, and PGvector
- 14:31 : Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
- 14:31 : How to Protect Your AI Agents from Prompt Injection Attacks: An Active Defense Approach
- 14:2 : Charities remain locked out of CAF Bank online accounts
- 14:2 : Moonshot AI Claims Kimi K3 Matches OpenAI and Anthropic Models
- 14:2 : CREST Launches AI-Enabled Pentesting Accreditation
- 14:2 : Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon
- 14:2 : Frontier Airlines Hit by Third Data Breach
- 14:2 : Huntress Flags Widespread Credential Stuffing Campaign Hitting SonicWall Devices
- 14:1 : US, Australia Release OT Isolation Guidance
- 13:31 : DEF CON 34 Badges Feature Open Source Security Chip
- 13:31 : Snowflake’s AI Agent Security Framework
- 13:31 : FTC sues Hims & Hers over health data sharing
- 13:31 : Wordfence Finds Critical Backdoor in ARVE WordPress Plugin
- 13:31 : Anthropic AI models breached three real companies
- 13:31 : Cybercrime goes subscription: AI, malware and infrastructure on demand
- 13:31 : Attackers abuse Microsoft auth for phishing
- 13:5 : IT Security News Hourly Summary 2026-07-31 15h : 8 posts
- 13:2 : What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery
- 13:2 : CVE-2026-63077 TeamCity RCE Vulnerability
- 13:2 : Keycloak Flaw Exposes Users’ Personal Data to Restricted Admins
- 13:1 : IBM: Average Data Breach Cost Hits $5M
- 12:31 : Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire
- 12:31 : 120 fake Walmart stores stealing credit cards
- 12:31 : XRP Volatility Surges as Cybersecurity Threats and Market Changes Raise New Concerns
- 12:31 : CISA adds Arista and Fortinet flaws to KEV catalog
- 12:2 : Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
- 12:2 : Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
- 12:2 : 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
- 12:1 : Mythos Asks the Right Question. It Doesn’t Answer It.
- 11:31 : Facial Recognition at Madison Square Garden
- 11:31 : Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
- 11:31 : Ransomware Killers Overwrite Security Process Memory Without Terminating Applications
- 11:31 : Fake Flash Player installs AtlasRAT
- 11:31 : Managing cyber-physical risk in smart buildings
- 11:31 : EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels
- 11:2 : Lights on! Real-time threat response with Red Hat Advanced Cluster Security
- 11:2 : Critical JetBrains TeamCity Flaw Enables Unauthenticated Remote Code Execution
- 11:2 : 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
- 11:1 : No time to lose: Why post-quantum security for financial services must start now
- 10:32 : Network Anomaly Detection in KATA
- 10:32 : Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace
- 10:32 : Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
- 10:31 : Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
- 10:31 : The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key
- 10:31 : Google Uses AI to Fix 1,072 Chrome Security Vulnerabilities
- 10:31 : Long-Lived Vulnerability in Microsoft Secure Boot
- 10:31 : The Average Cost of a Data Breach Rises to $5 Million
- 10:31 : The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
- 10:31 : AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks
- 10:5 : IT Security News Hourly Summary 2026-07-31 12h : 20 posts
- 10:2 : Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations
- 10:2 : 28 arrests in international strike against child sexual exploitation
- 10:2 : PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
- 10:2 : We found 120 fake Walmart stores trying to steal your credit card
- 10:2 : Anthropic’s Claude breached three companies during security tests
- 10:2 : ClickFix Campaign Uses EtherHiding to Hide Malware and Exposes DPRK Wallet Trail
- 10:2 : Expert panel: AI is writing the code. Who is defending it?
- 10:2 : Anthropic Finds Claude Breached Real Companies During Security Evaluations
- 10:2 : Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows
- 10:2 : Season 4 of The Europol Podcast available now
- 9:32 : Beyond the screenshot: Why you should verify what you see
- 9:32 : zipdump.py: Metadata Encoding, (Fri, Jul 31st)
- 9:32 : Critical Flaw Led to Azure Cosmos DB Pwnage
- 9:32 : AIDR: How CrowdStrike Is Defining the Next Era of Cybersecurity
- 9:32 : Fact Check: Clarifying claims about Europol’s operational processing environments
- 9:32 : The Oracle of Delphi Will Steal Your Credentials
- 9:31 : French-Spanish operation targets hazardous waste trafficking network: four arrested
- 9:31 : Beyond the Model: Harnessing Frontier AI for Stronger Cyber Defense
- 9:31 : When violence shapes identities in a larger pool of perpetrators: new Europol terrorism report
- 9:31 : CrowdStrike Falcon Platform Helps Meet U.S. Government Mandates for CISA BOD-26-04
- 9:2 : Anthropic Reveals Claude Escaped Testing, Breaching Three Companies
- 9:2 : Keep Your Tech Flame Alive: Trailblazer Rachel Bayley
- 9:2 : Migrant smuggling network using rental cars dismantled across the Balkans
- 9:2 : Critical Adobe Campaign Flaw Lets Attackers Execute Arbitrary Code
- 9:2 : BCON Collective uncovers shared phishing infrastructure linked to ShinyHunters
- 9:2 : Europol and Frontex strengthen cooperation with new Working Arrangement
- 9:2 : Threats Making WAVs – Incident Response to a Cryptomining Attack
- 9:2 : Europol-led action against nihilistic violent extremist network “The Com”
- 9:2 : BlackTech APT Uses New BlueShell Linux Backdoor in Attacks on Japanese Organizations
- 9:1 : Five arrests for smuggling migrants across the Bulgarian-Serbian green border
- 8:32 : The Nansh0u Campaign – Hackers Arsenal Grows Stronger
- 8:31 : Critical SolarWinds Web Help Desk Flaw Lets Attackers Bypass SAML Authentication
- 8:31 : Traefik Labs introduces Distro Zero secure runtime for API and AI gateways
- 8:31 : ICE’s New Detention Center Contracts Declare State Laws ‘Shall Not Apply’
- 8:31 : Horizon3.ai expands NodeZero with automated web application attack path testing
- 8:31 : Europol supports operation against amphetamine producers
- 8:31 : AttackIQ targets CTEM execution with AVA Agentic OS
- 8:2 : Recon-Only SSH Attack Leaves No Malware but Signals a Second-Stage Intrusion
- 8:2 : Researchers Warn of AI-Enhanced Phone Fraud Ecosystem
- 8:2 : SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign
- 8:2 : CareCloud Data Breach Impacts Over 350,000
- 8:1 : Resecurity expands threat intelligence integration ecosystem with IBM QRadar
- 7:31 : New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
- 7:31 : 22-Year-Old IPMI Flaw Exposes 24,000 Servers to Offline Password Cracking
- 7:31 : Analog Devices breach, Copilot AI worm, Teams ransomware vishing
- 7:5 : IT Security News Hourly Summary 2026-07-31 09h : 7 posts
- 7:2 : Critical Code Execution Vulnerability Patched in TeamCity
- 7:2 : PHP Patches 3 Security Flaws Enabling SQL Injection, Memory Corruption and DoS Attacks
- 7:2 : Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
- 7:2 : Chinese-Speaking Hacker Uses DeepSeek Agent to Launch Autonomous Cyberattacks