Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent…
Anthropic’s Claude escaped test sandbox to attack three organizations
Wrote and published malware during tests, which is apparently OK because leaky test environments were the real problem
Cryptominer Abuses Linux PAM to Hide From SOC Analysts
Cryptomining crew abandoned root to impersonate low-privileged Linux users and evade SOC alerts
Apple Patches Everything (July 2026), (Wed, Jul 29th)
I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets…
OpenAI’s rogue agent hit more victims, attackers hit 30 Minnesota water systems, Russian crew delivers weaponized e-mails in Exchange
OpenAI ‘Rogue Agent’ Fallout, Minnesota Water Systems Hit, Exchange OWA Zero-Click Mailbox Takeover David Shipley covers multiple security stories: the…
AiTM Phishing Becomes Top Initial Access Threat to Law Firms
AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats
Anthropic Says Claude Hacked 3 Organizations During Cybersecurity Tests
In a review triggered by OpenAI’s Hugging Face incident, Anthropic discovered three of its AI models had breached real organizations during third-party…
ISC Stormcast For Friday, July 31st, 2026 https://isc.sans.edu/podcastdetail/10032, (Fri, Jul 31st)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Friday, July 31st, 2026 https://isc.sans.edu/podcastdetail/10032,…
AI Escaped a Sandbox. That is Not What Should Worry You
What OpenAI’s and Anthropic’s testing incidents really teach defenders In the past two weeks, two of the world’s leading AI labs have disclosed the same…
Anthropic Says Claude Hacked Real Systems During Cybersecurity Tests
In a review triggered by OpenAI’s Hugging Face incident, Anthropic discovered three of its AI models had breached real organizations during third-party…
IT Security News Hourly Summary 2026-07-31 03h : 1 posts
1 posts were published in the last hour 0:31 : Leaky BMCs, Claude finds encryption flaws, Google’s new names
Leaky BMCs, Claude finds encryption flaws, Google’s new names
Thousands of server BMCs leak password hashes Claude finds flaws in encryption Google gives old threat actors new names Get the show notes here:…
Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App
Researchers linked the Flying Eagle Android RAT to fake police apps, uncovering 170 servers in a growing cybercrime ecosystem. Hunt.io researchers and…
What an SSH Tunnel Actually Does and When You Should Use One
Learn how SSH tunnels securely forward network traffic, when local, remote, and dynamic forwarding help, and why they are best for controlled, temporary…
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face’s…
CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems.
Top 10 Companies to Hire Power BI Developers in 2026
Compare 10 Power BI development companies for 2026, covering DAX, Microsoft Fabric, data engineering, security, compliance, AI, and enterprise BI project…
IT Security News Hourly Summary 2026-07-31 00h : 6 posts
6 posts were published in the last hour 22:2 : Apple Releases Security Updates Patching Nearly 200 Vulnerabilities Across macOS, iOS, iPadOS, and Safari 22:1 : Balancing speed and safety: A control framework for AI coding agents 21:55 : IT…
Apple Releases Security Updates Patching Nearly 200 Vulnerabilities Across macOS, iOS, iPadOS, and Safari
Apple has released security updates for its operating systems, addressing nearly 200 vulnerabilities. Thank you for being a Ghacks reader.
Balancing speed and safety: A control framework for AI coding agents
AI coding agents are part of the developer toolchain. Tools like Kiro and Claude Code generate features, tests, and code refactors from natural-language…
IT Security News Daily Summary 2026-07-30
210 posts were published in the last hour 21:31 : Bank of America to Acquire Cybersecurity Firm MDSec 21:31 : A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran 21:31 : What CISOs should take from the Hugging…
Bank of America to Acquire Cybersecurity Firm MDSec
The acquisition will add approximately 65 cybersecurity professionals to Bank of America’s operations in the United Kingdom.
A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
A memo obtained by WIRED, issued by the water utilities information sharing group WaterISAC, links dozens of cyberattacks against Minnesota water…
What CISOs should take from the Hugging Face-OpenAI incident
The recent Hugging Face-OpenAI incident is raising questions about how to secure AI as it becomes more autonomous and integrated into business…