PortSwigger has officially introduced Burp AT, an agentic AI assistant integrated directly into Burp Suite Professional. Now live…
Coordinated cyberattack hits 30+ Minnesota water utilities
A coordinated cyberattack struck operational technology systems at more than 30 community water utilities across Minnesota on July 26 and 27, 2024.
Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages
Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsoft’s legitimate…
Drone Follows Police Scotland Helicopter At Close Range
Drone passes within 50 feet of police helicopter, continues to follow it for about a minute in latest unmanned vehicle incident
Russian hackers exploit Exchange XSS flaw for mailbox takeover
A Russian threat group has exploited a cross-site scripting flaw in Microsoft Exchange to compromise email accounts at government agencies and private…
Mirage Kitten targets Middle East and Africa region with new malware
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger…
CISA sets a new SBOM baseline
The US Cybersecurity and Infrastructure Security Agency (CISA), together with its co-authoring partners, has released the 2026 Minimum Elements for a…
AtlasRAT Uses Four-Stage In-Memory Loader to Keylog and Inject Malware Into WeChat
AtlasRAT is a modular Windows remote access trojan that uses a four-stage, fully in-memory loader chain to quietly establish TLS‑ and ChaCha20‑protected…
Onyx Security Raises $113 Million to Control AI Agents in the Enterprise
The Series B funding round brings the total raised by Onyx Security to $153 million.
Apple Delays First Smart Glasses to WWDC 2027 Over Privacy Concerns
Apple has postponed the reveal of its first smart glasses to WWDC in June 2027, with sales anticipated later that year, according to Bloomberg analyst…
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file.…
‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale
Researchers warn that AI could turn dangling DNS takeovers into a nation-state weapon capable of disrupting governments, banks and global supply chains.
The Network Has Become the Control Plane for AI Security
Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing…
Check Point Brings AI Security into the Firewall with Industry-First AI Network Firewall
Check Point Software has launched what it calls the industry’s first AI Network Firewall, extending AI-specific inspection and control into the firewall…
SpaceX Starship Rocket Splashes Down After Successful Test
Forty-storey-tall Starship vessel carries out sub-orbital flight and splashes down in Indian Ocean in latest test
Nvidia opens AI security tent, Microsoft adds cyber sprinter to MDASH, Fairlife ransomware spills data
Nvidia opens the AI security tent Microsoft puts a cyber sprinter in MDASH Fairlife ransomware spills data Get the show notes here:…
Command Injection Cheatsheet: OS Payloads And Prevention (2026)
OS Command Injection is a critical vulnerability (CWE-78) where an attacker executes arbitrary operating system commands via a…
Orca Security secures AI-built and developer-created applications
Orca Security has announced two new AI-powered capabilities: Orca AI AppGen Security, which discovers and secures AI applications built outside the…
AutoIT Payload Injector , (Tue, Jul 28th)
For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it’s easy to write and powerful. Indeed, it…
CISA Adds Cisco Secure Firewall Management Flaw to Exploited Vulnerabilities List
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Cisco Secure Firewall Management Center (FMC),…
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The…
Shein Sees $99m Loss Ahead Of Hong Kong IPO
China-founded e-commerce company sees US market contract, falls to loss in first quarter as it prepares to list in Hong Kong
Houston City College – 831,642 breached accounts
In June 2026, Houston City College was the target of a ShinyHunters “pay or leak” extortion campaign . Data allegedly obtained from the college was later…
Should You Use AI for a Task? Here’s a Simple Way to Decide
This essay originally appeared in The Guardian . I teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto. And…
