Appeals panel rejects Amazon’s request for court order blocking Perplexity AI agents from accessing its service
Fake Open VSX Extensions Hijack AMD, Azure, Salesforce and Government Namespaces
Fake Open VSX extensions have hijacked high‑trust namespaces like AMD, Azure, Salesforce, Hyperledger, and a U.S. government agency on the Open VSX…
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
Bank of America impersonators weaponize ScreenConnect, then make it hard to remove
A phishing campaign impersonating Bank of America (BoA) is underway, trying to trick Windows users into installing ScreenConnect remote access software…
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Execute Code Remotely
Veeam has issued security updates to address multiple vulnerabilities in Veeam ONE, including a critical flaw that could enable an unauthenticated remote…
Ukrainian Drones Strike More Wildberries Warehouses
Drones have burned down 13 Wildberries e-commerce logistics facilities over past 18 days, Ukraine officials say
Frontier Models Engage in Unsanctioned Behavior During Testing
Anthropic and OpenAI models attacked “real people and organizations” during AI Security Institute tests
Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds With Automatic Device Isolation
Ransomware can turn one careless click into a business-wide emergency. An incident at QNET shows how quickly that risk can grow when attackers use trusted…
Security Awareness in Municipalities: ‘You Need Staying Power and Strong Nerves’
Cyberattacks on town halls and district offices are no longer the exception. How do municipalities protect themselves against them? And what role does the…
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
An agent running Anthropic’s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber…
Blackstone Eyes Major Debt Deal For Anthropic Chip Access
Asset manager reportedly discusses debt deal that could exceed size of earlier $35bn package to finance lease of Google AI chips
7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen
Windows can protect users before a suspicious download runs. But a newly documented 7-Zip behavior can remove an important warning layer and allow a…
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV)…
Hotel Wi-Fi Attacks Linked to Russian Hackers Target Microsoft 365 Accounts With Custom Malware
In a sophisticated cyber campaign carried out by attackers using hotel and conference Wi-Fi networks, Microsoft uncovered the theft of Microsoft 365…
Fake Bank of America Phishing Scam Installs Remote Access Malware
Cybercriminals are using a fake Bank of America phishing campaign to trick users into downloading a malicious script that installs ScreenConnect, enabling…
Botnet Is Hunting Router Ping Tools That Can Turn User Input Into Shell Commands
A botnet campaign is probing routers for weak spots in diagnostic features. The activity focuses on web paths linked to ping, traceroute and…
Ransomware Hackers Are Hiding Malware Command Servers Inside Ethereum Smart Contracts
Ransomware operators are now abusing Ethereum smart contracts as stealthy command‑and‑control resolvers, with a Gentlemen ransomware affiliate using the…
Cloudflare gives AI agents wallets with built-in spending controls
Cloudflare’s Wallets will give AI agents running on its platform a human-readable wallet handle for paying APIs and online content within limits set by…
ChainDrop hits npm, Pass-ta-key targets passkeys, AI runs amok in Africa
ChainDrop attack hits npm Pass-ta-key attacks target passkeys AI accounts for most cybercrime in Africa Get the show notes here:…
Water Sector Cyberattacks Reportedly Hit at Least 12 States
Georgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption.
Apple Seeks Immediate Court Order In OpenAI Trade Secrets Case
iPhone maker seeks preliminary injunction to stop OpenAI from using allegedly stolen proprietary data to develop hardware
Kali365 Exploits Microsoft Device Login to Access US Corporate Data
Learn how Kali365 has been abusing Microsoft device login to gain OAuth tokens, targeting US firms, and how SOC teams can detect, hunt, and stop these…
CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Apache Tomcat flaw, tracked as CVE-2026-34486, to its Known…
MiniMax Excludes US, Europe From Open Video AI Release
Shanghai-based start-up releases major video-generation model under open-weight licence, but excludes major markets over legal concerns