Voice phishing is no longer limited to a convincing phone call and a fake sign-in page. A newly examined criminal platform called Work Panel brings target…
GitLab Fixes 13 Security Flaws That Can Leak Data, Alter Pipelines, and Crash Servers
GitLab has released critical security updates to address 13 vulnerabilities that could potentially expose sensitive data, manipulate CI/CD pipelines, and…
Google Releases Patches for 370 Vulnerabilities in Chrome 151
The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flaws
Claude Worldwide Outage Disrupts Users With “Request Failed With 529 Overloaded” Message
Anthropic’s Claude AI platform suffered a worldwide outage on July 29, 2026, causing failed prompts, slow responses, interrupted conversations, and…
1 in 5 Data Center Assets Are Within Easy Reach of Attackers
Claroty has analyzed 750,000 cyber-physical systems across some of the world’s largest data center facilities.
Linux Cryptomining Campaign Weaponizes PAM to Hide XMRig Botnet Activity
A new Linux cryptomining campaign has surfaced using a rare trick to stay hidden inside compromised networks. Instead of behaving like typical malware,…
Coordinated cyberattack hits more than 30 Minnesota water utilities
A coordinated cyberattack on July 26 and 27 hit operational technology (OT) systems at more than 30 community water utilities across Minnesota, prompting…
A Two-Minute Microsoft Teams Call Could End With Your Network Encrypted With Ransomware
A short Microsoft Teams call can now become the first step in a ransomware attack. Attackers posing as IT support staff are persuading employees to grant…
eSIM Plus and Nicegram Share Belarus-Linked Codebase, Analysis Finds
Analysis found eSIM Plus and Nicegram share a Belarus-linked codebase, while eSIM Plus routes data and calls through Russian services. Two popular apps…
Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy Chaos Ransomware
Hackers are abusing Microsoft Teams voice calls and fake IT helpdesk personas to gain remote access to corporate endpoints, drop a custom…
NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Devices
The UK’s National Cyber Security Centre wants network device makers to improve forensic observability
Russia Issues Arrest Warrant For Telegram’s Durov
Telegram allegedly used by Ukrainian security services to recruit Russians to carry out sabotage, Russian authorities say
Rogue OpenAI Agents Breached Four Third-Party Services
Out-of-control AI models accessed four third-party services in addition to hacking Hugging Face, OpenAI says
Work Panel Vishing Platform Automates Enterprise Account Takeovers and MFA Theft
Work Panel is a turnkey vishing and phishing platform that industrializes enterprise account takeovers and MFA theft by packaging infrastructure…
Shein Faces FTC Probe Ahead Of Hong Kong IPO
Cross-border fast-fashion retailer discloses that US trade regulator is investigating it, as it prepares for flotation
Toy Ghouls’ new toy: the GenieLocker ransomware
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls,…
Meta, BlackRock To Jointly Fund Texas AI Data Centre
Under the deal to finance the $14bn data centre near El Paso, BlackRock will end up owning 80 percent of the 1 GW project
US and Allies Update SBOM Guidance
Five years after the initial release, the refresh introduces new elements, removes others, and updates terminology.
Hackers Steal Data On Thousands From Education Department
Data breach affecting DfE help desk, Turing Scheme steals 607,000 records, data reportedly offered for sale online
Chrome 151 Patches 370 Vulnerabilities
The major browser update resolves roughly 80 critical- and high-severity security defects.
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another…
ShinyHunters Claims Responsibility for EY Data Breach as Investigation Continues
The cyberattack involving Ernst & Young (EY) has entered a new phase after the ShinyHunters extortion group claimed responsibility for the intrusion,…
FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move…
OpenAI agent reaches Modal, Minnesota water systems hacked, fake Russian companies steal real money
OpenAI agent’s escape reaches a Modal customer Hackers hit Minnesota water systems Fake Russian companies, real stolen money Get the show notes here:…