Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems.
Word worm crawls into Copilot, spreads chaos
Researcher says months of coordination with Microsoft have yet to produce a robust mitigation
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle…
CrashStealer Malware Targets macOS Users by Posing as Apple Crash Reporter
A newly identified malware strain named CrashStealer is targeting macOS users by disguising itself as Apple’s legitimate crash reporting utility. Designed…
Hackers Can Hijack Tor Browser Users Through a Single Malicious Web Page
A single malicious webpage is enough to compromise Tor Browser users running an unpatched build, following newly disclosed research into CVE-2026-10702.…
US Sanctions on VPN Service Briefly Disrupt Telegram’s t.me Link Shortener Due to Compliance Action
iTelegram’s t.me link-shortening domain briefly went offline earlier this week after a compliance action linked to US sanctions inadvertently affected the…
In the Mythos era, security belongs at runtime
Frontier AI cut time-to-exploit from years to hours. Why defense now has to happen at runtime.
Google to Patch Gemini Flaw That Lets Locked Android 16 Phones Send SMS and WhatsApp Messages Without PIN
Google is preparing to roll out a fix for a newly identified security vulnerability in its Gemini AI assistant that could allow unauthorized users with…
A week in security (July 20 – July 26)
A list of topics we covered in the week of July 20 to July 26 of 2026
Russian Intelligence Hackers Phish Signal Backup Keys to Hijack Accounts and Messages
Russian intelligence-linked hackers are trying to seize Signal accounts by posing as support staff and asking targets for backup recovery keys. The…
WP2Shell WordPress Exploit Technical Analysis and Real Attack Data
On July 17th, 2026, the WordPress Security Team released updates to WordPress core addressing a critical vulnerability chain that can be leveraged by…
macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets
Mac users are being targeted by a ClickFix campaign that turns a fake verification prompt into a path for malware installation. Victims are persuaded to…
Microsoft Threat Intelligence Portal Retires August 1: 4 Checks Before the Cutoff
Microsoft is retiring its legacy Threat Intelligence portal on August 1. Security teams should verify licenses, permissions, investigation projects, APIs,…
Critical Ruflo MCP Bridge Flaw Lets Attackers Execute Commands and Hijack AI Agents
A critical security flaw in the open-source AI orchestration platform Ruflo has been disclosed, allowing unauthenticated attackers to execute arbitrary…
Building Trustworthy Agentic AI: How Security Concerns Have Changed in 2026
2026 is touted as the year AI moves from speculation and interest to real-world deployment and value. Yet one global analyst firm predicts 40% of agentic…
NVIDIA BlueField Vulnerability Enables Code Execution Attacks
NVIDIA has disclosed a serious vulnerability affecting its BlueField DPUs and ConnectX networking platforms that could allow attackers to execute code on…
MCBS Healthcare Data Breach Affects 1.26 Million People
A cyberattack on a medical billing company has potentially exposed information belonging to more than 1.26 million people, underscoring that healthcare’s…
Hijacked Joyfill npm Packages Deploy Worm-Like RAT and Steal Developer Credentials
A fresh supply chain scare hit software teams after attackers slipped malware into trusted open source libraries. On July 28, 2026, malicious beta builds…
IT Security News Hourly Summary 2026-07-29 18h : 9 posts
9 posts were published in the last hour 16:2 : Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory 16:2 : LogoKit Phishing Kit Screenshots Victim Sites in Real Time 16:2 : Ernst & Young Notifies Clients…
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI…
LogoKit Phishing Kit Screenshots Victim Sites in Real Time
LogoKit now builds per-victim phishing pages using live screenshots of the target’s real website
Ernst & Young Notifies Clients Following Third-Party Support Platform Data Breach
The company Ernst & Young (EY) has sent out notices to the affected clients about the data breach involving the third-party support ticket platform, which…
Google goes it alone with a new cybercrime crew taxonomy
So much for Microsoft and CrowdStrike’s plans for consistent names across the industry
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been…