So-called “wrench attacks” have resulted in $30m in losses so far in 2026, says Chainalysis
AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses…
Snowflake hacker pleads guilty, faces up to 32 years in prison
A Canadian man is facing decades in prison for hacking customer accounts at cloud storage provider Snowflake and stealing data from more than 165…
Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts
Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched.
Vanta Stealer Uses PyArmor to Steal Browser Passwords, Crypto Wallets and Discord Tokens
Vanta Stealer is a Python‑based, cross‑platform information stealer that uses layered PyArmor obfuscation on top of a PyInstaller‑packed executable to…
Critical Jenkins Vulnerability Allows Attackers to Execute Malicious Code on Controller
Jenkins has disclosed a critical security vulnerability that could allow attackers to execute malicious code on a Jenkins controller by bypassing a…
Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses
Cybersecurity researchers have disclosed a security issue with Apple’s iCloud Private Relay tool that can expose a user’s real IP address. Introduced with…
OWASP Releases GenAI LLM Top 10 2026 for Building and Securing Modern AI Apps
The Open Web Application Security Project (OWASP) has officially released the Top 10 for LLM Applications 2026, a foundational security guide targeting…
Three in four AI-generated vulnerability patches leave something broken
Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write.…
Remus Hides Its Command Server on Ethereum While Emptying Browser Vaults
Remus is a newly active information‑stealing malware that quietly slips into Windows systems, locks onto popular web browsers, and drains their saved…
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains. Introduced in the…
Public PoC Released for Linux Kernel Bridge Use-After-Free Vulnerability
A public proof-of-concept has been released for a use-after-free flaw affecting the Linux kernel’s bridge subsystem, specifically its Spanning Tree…
Amazon and Apple impersonated in “$149.99 unauthorized charge” scam
Different logos, different color schemes, same scam.
Discounted Claude access bought on the gray market may expose every prompt you send
More than half a dozen services advertised on underground forums and messaging platforms, offering discounted or “unlimited” token access to frontier AI…
Critical Paperclip Flaw Allowed Admin Access, Code Execution
An attacker could self-register, sign in for board-level API access, and import a new company for code execution.
IT department put sticky notes on the laptops to help employees log in
Leaving this information exposed allowed someone else to gain access
Critical Jenkins Deserialization Flaw Allows Attackers to Execute Code on Controllers
A critical vulnerability in Jenkins, tracked as CVE-2026-70426, may allow attackers to execute arbitrary code on Jenkins controllers by bypassing…
OpenAI Agents Discover Zero-Day and Leave the Door Open for Other Models
OpenAI has revealed at the Black Hat security conference that AI agents involved in a cybersecurity evaluation found previously unknown vulnerabilities…
Kill switch fears now rival ransomware as a top security risk for European businesses, Proton study finds
For years, the security team’s job has been to defend against cyberattacks. New research from Proton suggests that job now needs to extend to a very…
Adversarial Clothing Designed to Fool Facial Recognition Systems
There are many companies manufacturing adversarial clothing designed to confuse facial recognition systems. It’s a cool idea, but I worry that it’s mostly…
16-31 July 2026 Cyber Attacks Timeline
103 confirmed cyber incidents reported between 15 and 31 July 2026 — including attacker motivations, top techniques, initial access vectors, hardest-hit…
Anthropic’s Mythos AI used social engineering to target real people
Testers found that Anthropic’s AI agent Mythos attempted to social engineer Github developers into accepting malicious code.
KHunt Toolkit Turns Oracle SQL Injection Into SYSTEM-Level RCE and Credential Theft
KHunt shows how a “routine” SQL injection against an Oracle‑backed web app can be weaponized into SYSTEM‑level remote code execution and credential theft…
Meta AI Model Gained Internet Access and Hacked Another Organization’s Network
Meta has disclosed that one of its AI models gained unintended access to the internet during a cybersecurity evaluation and then exploited a vulnerability…