Atomic Stealer is being pushed at Mac users through websites that look harmless. A large ClickFix operation uses more than 250 look-alike domains to steer…
Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability
Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution.
Cisco Patched Multiple Critical Vulnerabilities in Catalyst SD-WAN – Update Now
Cisco has rolled out software hardening updates for its Catalyst SD-WAN Software after an internal security review uncovered multiple critical…
OWASP 2026 LLM Top 10: “The model will be fooled”
The OWASP GenAI Security Project has released the 2026 edition of its Top 10 for LLM Applications and, for the first time, the list was influenced by…
Apple iCloud Private Relay WebKit Flaws Leak Users’ Real IP Addresses
Apple users who rely on iCloud Private Relay to conceal their online location may not be getting the protection they expect. Newly disclosed flaws in…
250+ Fake Download Domains Target Mac Users With AMOS and MacSync Infostealers
Attackers are using more than 250 fake “download” domains to selectively target Mac users with AMOS and MacSync infostealers, hiding their ClickFix lures…
Suppliers, logins, and AI tools are all becoming attack paths
Cybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while…
Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records
Snowflake hacker Connor Moucka pleads guilty after breaching 165 organizations, stealing billions of records, and extorting victims. Connor Riley Moucka,…
Hackers Abuse Cloud Startup Credits to Resell Claude and Gemini AI Access
Threat actors are exploiting free cloud trials and startup credit programs to build gray-market AI proxy services. These services resell discounted access…
Browser security is where software, data, and AI meet
In this interview with Help Net Security, Rui Ribeiro, CEO of Jscrambler, explains why the browser has become a security problem organizations do not…
Non-human identities are 91% of everything active in production
A backup job fires at two in the morning. A scanner walks the same AWS account an hour later, a deployment pipeline assumes a role at four, and a logging…
Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway
It’s just a remote maintenance function, says Zbtlink
Critical Cisco SD-WAN Flaws Expose Systems to Access Control Bypass Attacks
Cisco has released important security updates for Catalyst SD-WAN Software after discovering several critical vulnerabilities that could allow for access…
Cloudflare OS goes open source with a record of everything its agents read
Cloudflare open sourced Cloudflare OS, the agent platform whose first version its own employees have used since May. Every resource an agent reads gets…
Inter-Con Security – 276,114 breached accounts
In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published data it alleged was…
OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack
It started with an ‘impossible task’ and led to AI deciding it needed to act as a collective intelligence
ISC Stormcast For Thursday, August 6th, 2026 https://isc.sans.edu/podcastdetail/10040, (Thu, Aug 6th)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Thursday, August 6th, 2026 https://isc.sans.edu/podcastdetail/10040,…
22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)
[This is a Guest Diary by Daryl Jiminez, an ISC intern as part of the SANS.edu BACS program]
OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
At the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies—and did it all…
OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
Researchers at security firm Zenity found more than a dozen flaws in AI browsers—and managed to get OpenAI’s Atlas to make an unauthorized Amazon purchase.
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers. His work shows they pulled off intrusions in a…
Black Hat 2026: Key news, takeaways and security trends
Black Hat USA 2026 returns for its 29th year, covering the latest in infosec for CISOs, technical experts, thought leaders, innovative vendors and…
Oracle SQL Injection Attack Enables Remote Code Execution
A Huntress investigation reveals how attackers used SQL injection to achieve RCE and steal credentials.
Western government leaders call for a focus on infrastructure resilience, not AI hype
U.S. and allied officials said companies should start preparing now for a cyberattack that changes how they provide essential services.