The European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other…
Californians can tell data brokers to DROP their information
California has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all…
BSides 2026: How AI Agents Really Perform in Offensive Security
BSides 2026 research shows AI agent behavior reveals more than benchmark scores.
Google dev kit spurs first-ever agent-on-agent violence
Poisoned pull requests contain prompt injection that allows one to control another
Claude Opus 5 Vending Test Shows Profit-Driven AI Risks
Claude Opus 5 set a Vending-Bench record while fabricating supplier bids, breaking truces, and ignoring refunds, showing why companies need stronger AI…
Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities
Google is testing twice-weekly Chrome security updates as AI tools uncover more vulnerabilities and the company works to shrink the browser’s patch gap.
Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated
OpenAI and Anthropic admitted that their unreleased AI models escaped their sandboxes and hacked several companies in unprecedented cyberattacks. Who is…
Coldcard RNG Flaw Linked to Suspected $88.6M Bitcoin Theft
A Coldcard RNG flaw may have exposed predictable wallet seeds linked to $88.6 million in suspected Bitcoin thefts across 4,585 addresses.
IT Security News Hourly Summary 2026-08-03 21h : 4 posts
4 posts were published in the last hour 19:2 : 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users 19:1 : Malware Can Steal Your Google Synced Passkey Without Asking for Your Password or Fingerprint 19:1 : Apple…
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote…
Malware Can Steal Your Google Synced Passkey Without Asking for Your Password or Fingerprint
New research reveals that malware already sitting on a compromised Windows PC can hijack Google’s synced passkeys and take over accounts without ever…
Apple challenges UK government’s latest demand for iCloud backdoor: report
Apple has appealed a new legal demand by the U.K. government, which critics say could threaten the privacy rights of users all over the world.
Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations
The list of people behind companies, foundations and trusteeships is part of efforts to combat money laundering and terror financing.
COLDCARD Seed Generation Flaw Linked to Nearly $89 Million Bitcoin Theft
Galaxy Research linked a suspected Bitcoin theft of 1,367.05 BTC to weak COLDCARD seeds. Coinkite says updates cannot repair seeds already generated on…
N-able N-central Vulnerability Under Active Exploitation
Threat actors are actively exploiting an N-able N-central vulnerability that can grant unauthenticated administrative access.
AI slop pollutes the CVE pipeline with fake vulns
With NIST still buried under its backlog, expect AI-generated bogus reports to continue
DNA Test Software Vulnerability Allows Attackers to Alter Analysis Data
Thermo Fisher Scientific has disclosed a high-severity security flaw affecting several of its Applied Biosystems Human Identification (HID) software…
More on the OpenAI Agent’s Attack on Hugging Face
Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based…
Amazon Links Four npm Supply-Chain Attacks to North Korea’s Sapphire Sleet
Amazon linked four npm supply-chain attacks to North Korea’s Sapphire Sleet, exposing the security risks posed by compromised maintainer accounts.
Public PoC Released for Critical Rails Active Storage RCE Vulnerability
A critical vulnerability in Ruby on Rails has raised new concerns about cloud data breaches, particularly for companies that host customer platforms in…
Hugging Face Breach Raises Concerns Over AI-Driven Attacks
Hugging Face is investigating a security incident after its production infrastructure was compromised in an intrusion the company says involved an…
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at…
AI Runs the Hack: Chinese Actor Automates Cyberattacks With DeepSeek
Unit 42 uncovered an AI-driven Chinese hacking campaign where DeepSeek autonomously scanned targets, selected exploits, and launched attacks. Researchers…
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
The INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access…