Researchers pitted a person against a Claude agent and found that, after a week of texting, the AI chatbot was more effective at creating “exploitable…
Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)
Most phishing campaigns rely on the fact that the victim is afraid to loose “something”: money, access to information, … Many brands have been…
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images,…
IT Security News Hourly Summary 2026-08-01 09h : 3 posts
3 posts were published in the last hour 7:1 : MacSync Stealer RAT Uses Fake Claude Guides to Steal Passwords and Crypto Wallets 7:1 : This month in security with Tony Anscombe – July 2026 edition 6:31 : SplitVPN –…
MacSync Stealer RAT Uses Fake Claude Guides to Steal Passwords and Crypto Wallets
A newly disclosed macOS malware campaign dubbed MacSync weaponizes fake Claude AI installation guides to deploy a six-stage stealer and remote access…
This month in security with Tony Anscombe – July 2026 edition
OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat made for a packed July roundup
SplitVPN – 865,336 breached accounts
In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach . The incident exposed millions of customer records,…
What Is Polymarket? How Blockchain Is Transforming Prediction Markets
Prediction markets have existed for decades as a way to forecast future events, but blockchain technology has reshaped how they operate. Among the…
Arch Linux Disables AUR Package Takeovers as Attackers Push Malicious Commits
Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) after security teams detected a wave of malicious takeovers and…
IT Security News Hourly Summary 2026-08-01 06h : 2 posts
2 posts were published in the last hour 4:1 : Google Releases Patches for 370 Vulnerabilities in Chrome 151 3:31 : HackerOne Mandates ID Verification for Bug Bounty Submissions
Google Releases Patches for 370 Vulnerabilities in Chrome 151
The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flaws
HackerOne Mandates ID Verification for Bug Bounty Submissions
HackerOne has confirmed that all hackers must now complete identity verification before submitting reports to any bug bounty program (BBP) on its…
Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
A Chinese-speaking threat actor has been using DeepSeek’s AI models to orchestrate cyber-attacks targeting Asian organizations
Healthcare Cybersecurity in 2026: Healthcare CISO Matt Burke on AI, MFA, SOCs & Incident Readiness
On Cybersecurity Today on the Weekend, host David speaks with Matt Burke, CISO of Bespoke Concierge MD, a telemedicine provider with doctors licensed in…
The Department of Know: Minnesota water hack, LLM finds encryption flaw, human error hit Hugging Face
This week’s Department of Know is hosted by Rich Stroffolino , with guests Janet Heins , CISO, ChenMed , and Derek Fisher , Director of the Cyber Defense…
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another…
ShinyHunters Claims Responsibility for EY Data Breach as Investigation Continues
The cyberattack involving Ernst & Young (EY) has entered a new phase after the ShinyHunters extortion group claimed responsibility for the intrusion,…
Toy Ghouls’ new toy: the GenieLocker ransomware
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls,…
NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Devices
The UK’s National Cyber Security Centre wants network device makers to improve forensic observability
IT Security News Hourly Summary 2026-08-01 00h : 16 posts
16 posts were published in the last hour 22:2 : CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft 22:2 : OpenAI agent reaches Modal, Minnesota water systems hacked, fake Russian companies steal real money 22:2 :…
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related…
OpenAI agent reaches Modal, Minnesota water systems hacked, fake Russian companies steal real money
OpenAI agent’s escape reaches a Modal customer Hackers hit Minnesota water systems Fake Russian companies, real stolen money Get the show notes here:…
Anthropic Says Claude Found New Attacks on HAWK and Reduced-Round AES
Anthropic says Claude Mythos improved attacks on HAWK and reduced-round AES-128, though production encryption systems remain unaffected.
South Korea Warns of State-Backed Watering Hole Attacks
South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies…