A compromised GitHub account fueled a supply chain attack, spreading credential-stealing malware across hundreds of packages.
OWASP Subtractive Security Top 10 Project Released to Identify and Reduce Cyber Risks
The Open Worldwide Application Security Project, or OWASP, has introduced the Subtractive Security Top 10 Project, a security engineering initiative…
Rapid7 Releases Metasploit Framework 6.5 | MCP AI Integration And Malleable C2
Rapid7 has officially launched Metasploit Framework 6.5, packing two years of core development, 422 new modules, and major…
CISA Warns of N-able N-central Authentication Bypass Vulnerability Exploited in Attacks
CISA has warned that attackers are actively exploiting a critical authentication bypass vulnerability in N-able N-central. Tracked as CVE-2026-18577, the…
INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit
INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations.…
Public PoC Released for CUPS Vulnerability Allows Attackers to Gain Root Privileges
A public proof-of-concept (PoC) has been released for CVE-2026-39875, a macOS vulnerability in the Common UNIX Printing System (CUPS) that allows an…
AI helps Microsoft bug hunters chase a record $20M payday
Broader bounty rules added to a swelling volume of machine-assisted vulnerability reports
Six Flowise RCE Flaws Let Attackers Execute Code on AI Workflow Servers
Flowise servers used to build AI agents and automated workflows are facing six newly disclosed remote code execution flaws. The weaknesses could allow…
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom…
WhatsApp Scam Hijacks Accounts via Linked Devices Feature
WhatsApp scam abused the Linked devices feature to hijack accounts without stealing any passwords
Critical cPanel Flaw Lets Hosting Users Grab Database Root Access | CVE-2026-58048
A critical security vulnerability patched in cPanel could allow authenticated web hosting users to cross privilege boundaries and…
AI developers targeted via trojanized GitHub repositories
Cybercriminals are cloning popular GitHub repositories for AI tools and developer resources to distribute an infostealer, according to Netskope Threat…
Cyber Briefing: 2026.08.04
Malicious actors and rogue insiders are systematically exploiting public Wi-Fi networks, AI-assisted phishing tactics
Six Flowise Vulnerabilities Enable Remote Code Execution on AI Workflow Servers
Six newly disclosed vulnerabilities in Flowise, a popular open‑source platform for building AI agents and LLM workflows, allow unauthenticated and…
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple…
Sevii APS Module preempts attacks with autonomous cyber defens
Sevii has announced a major expansion of the Sevii Autonomous Defense & Remediation (ADR) platform with the general availability of an Autonomous…
Weaponized Email AI Assistants Could Help Attackers Hijack Accounts
Researchers demonstrate how attackers could abuse built-in email chatbots to evade detection, impersonate trusted employees, compromise executive…
DarkSword Server Combines iPhone Exploits With Fake Apple ID Login Page
DarkSword’s leaked iOS exploit chain is now powering a fast‑moving server cluster that marries one‑click Safari exploitation with a convincing fake Apple…
Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple Sessions
Talos read attacker prompt logs and found guardrails fell to task splitting and ownership claims
ServiceNow organizes autonomous security around six solution areas
ServiceNow has announced an acceleration of its Autonomous Security vision with six unified solutions that help deliver prevention-first, AI-native cyber…
Zenity Raises $125 Million in Series C Funding
The AI security company will invest in product innovation, global expansion, and customer experience.
Joinable Labs launches threat intelligence platform
Joinable Labs has introduced Joinable Security, a new threat intelligence platform designed to help security teams track adversary behavior and automate…
Snyk unveils continuous AI pentesting and agent red teaming
Snyk has announced the general availability of Evo Continuous Offensive Security (COS), enabling security teams to continuously test applications with…
Fake Xeno Roblox Cheats Deliver Java RAT That Steals Discord and Gaming Accounts
Fake Roblox cheat tools are once again being weaponized, with a newly observed campaign distributing a sophisticated Java-based remote access trojan (RAT)…