77 counterfeit Open VSX extensions beaconed to one domain, 19 harvesting git and CI identity
Top product launches at Black Hat USA 2026
Black Hat USA 2026 is underway in Las Vegas, and vendors are using the moment to unveil what they hope will define the next year of defense. Here are the…
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes…
White House walks tightrope on securing AI without stifling tech innovation
National Cyber Director Sean Cairncross said the administration wants to work collaboratively with the private sector.
RansomHouse Claims Responsibility for Cyberattack Disrupting Nichirei Operations in Japan
Japanese frozen-food and logistics company Nichirei is currently dealing with an unknown cyberattack that caused the disruption of the firm’s nationwide…
U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited…
Black Hat USA 2026 – Summary of Vendor Announcements (Part 3)
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root
OVSwrap is a 13-year-old Linux kernel flaw that lets local users gain root privileges on most distributions using Open vSwitch. Security researcher Asim…
“I’m Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails
Cisco Talos found hackers using simple authorization claims to bypass AI guardrails, build DDoS attack tools, steal credentials and access live camera…
Cyber Briefing: 2026.08.05
Security risks are shifting from unpatched infrastructure and massive cloud data exposures toward architectural vulnerabilities and governance
Stolen Greatness Tokens Provide Microsoft 365 Access More Than Two Weeks After Phishing
Stolen Greatness authentication tokens are providing sustained, MFA‑approved access to victim Microsoft 365 tenants for more than two weeks after the…
77 Evil Twin Open VSX Extensions Exfiltrate Private Git Repository and CI Data
A wave of counterfeit Open VSX extensions has exposed how easily a familiar developer tool can become a data collection channel. Seventy-seven packages…
Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP…
Stellar Cyber’s Auto-Triage AI matches human analysts 99.7% of the time
Stellar Cyber, the full-cycle AI-native security operations platform company, today released results from an independent study of 124 days of customer…
Paperclip AI Flaws Let Unauthenticated Attackers Run Commands
3 Paperclip flaws exposed data & allowed unauthenticated command execution in two deployment modes
Agentic AI Security: The Chatbot Era Is Already Over
There is a diagram most security teams still carry in their heads when they think about AI. A user talks to a chatbot. The chatbot talks to a large…
OpenAI Says AI Agent Breached Hugging Face During Cybersecurity Test
OpenAI has disclosed that one of its advanced artificial intelligence agents autonomously breached the boundaries of a controlled cybersecurity evaluation…
New OVSwrap Linux Vulnerability Lets Attackers Gain Root Access
A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-64531 and dubbed OVSwrap, allows unprivileged local users to escalate privileges to root…
Four Million Malware Reports Reveal a Widespread No-DNS C2 Blind Spot
A long‑running supply chain compromise of the QuickFox VPN accelerator that quietly delivered an FDMTP backdoor to carefully profiled Windows systems,…
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
Three distinct Phishing-as-a-Service (PhaaS) platforms, Sneaky 2FA, EvilTokens, and EvilProxy, are actively targeting US organizations to steal Microsoft…
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and…
Django Urges Immediate Upgrade to 6.0.8 and 5.2.17 After Four Security Fixes
The Django development team has released Django 6.0.8 and Django 5.2.17 to fix four security vulnerabilities affecting supported versions of the Python…
Shadow AI, Rogue Agents, and Data Leaks: A Special Report on Navigating AI Risk
Discover top enterprise AI risks — from shadow AI to rogue agents and data leaks — plus practical CISO strategies in the new Akamai SOTI special report.
15 TP-Link Omada ZTP Flaws Enable Router Hijacking and Root Code Execution
A set of 15 vulnerabilities in TP-Link’s Omada Zero-Touch Provisioning (ZTP) could enable attacks against enterprise networks, with the findings set to be…