Cybercriminals spent July 2026 proving that trusted business utilities including Microsoft authentication pages, Zoom event invitations, and official…
Don’t Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT,…
Google Blogger Locked Legitimate Websites After Mistaking Them for Malware
Thousands of Blogger website owners woke up this week to a jarring surprise: their perfectly legitimate blogs had been locked and slapped with a “Malware…
From 2 weeks to 2 minutes: Amazon Cognito launches Provisioned limits for self-service rate limit management
Imagine preparing for your biggest sales event of the year, and you want to ensure your customer identity management service can handle the elevated…
Poison Claude is Selling Cheap AI Tokens Built on Fake Accounts and Free Credits
A shadowy online service called Poison Claude is reselling access to Anthropic’s premium AI models at a significant discount. Researchers suggest that…
Prisma AIRS – Unified Data Protection for Claude
As AI adoption shifts from experimental tools to the business core, enterprises are deploying AI agents and assistants across every department. Developers…
IBM’s agentic AI platform is under active attack – patch now
A critical Langflow flaw allowing RCE on default deployments is being exploited, says the CISA
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on…
Greatness PhaaS Bypasses Email Security and MFA to Hijack Microsoft 365 Accounts
Greatness has emerged as a phishing-as-a-service platform designed to steal Microsoft 365 access at a time when many organizations assume multi-factor…
Salt Security Launches Industry-First AWS WAF Managed Ruleset for AI Agents and API Protection
Salt Security has unveiled what it says is the industry’s first AWS WAF managed ruleset designed specifically to protect both APIs and AI agents,…
Crypto Protocols Lose $35M in Coordinated Attacks
In a alarming six-hour window on July 23, 2026, Bitcoin- and Ethereum-linked protocols suffered multiple exploits draining over $35 million in combined…
CISA is prioritizing work with critical infrastructure as it begins to recover from cuts
The agency has been focused on helping secure systems at drinking and wastewater utilities in recent weeks.
PSA: Apple’s Private Relay can leak your real IP address
A bug in how Apple implements its Private Relay feature, which in theory masks users’ IP addresses from the sites they visit, can reveal users’ real IP…
Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals
Brown Health Medical Group-MA breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. Brown…
5 Best AI Detection & Response Platforms for 2026
Compare AI detection & response platforms for 2026, including Dash, Lakera, Operant AI, HiddenLayer and Prisma AIRS, for runtime threat protection and…
Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
More than 50 offending image and video ads were published across Facebook, Instagram, Messenger, or Threads, according to Meta’s ad library data. Some ran…
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP…
Microsoft Awards Record $20 Million to 562 Researchers in Biggest Bug Bounty Year
Microsoft has awarded more than $20 million to 562 security researchers through its bug bounty program, marking the largest annual payout in the company’s…
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer’s computer. Paperclip is an open-source control…
Cybersecurity Skills Gap: More Than Just a Workforce Challenge
Learn why the cyber skills gap is a business risk according to the Fortinet 2026 Cybersecurity Skills Gap Report findings.
SMOKE#SCREEN Campaign Abuses ScreenConnect RMM and Cloudflare Tunnels to Hijack Windows and macOS Systems
SMOKE#SCREEN is a campaign that turns ordinary software updates and business files into a doorway for remote control. Victims who run the files can…
Fake Open VSX Extensions Harvest Private Repo and CI Data
77 counterfeit Open VSX extensions beaconed to one domain, 19 harvesting git and CI identity
Top product launches at Black Hat USA 2026
Black Hat USA 2026 is underway in Las Vegas, and vendors are using the moment to unveil what they hope will define the next year of defense. Here are the…
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes…