Iran-nexus hackers are suspected in a broad campaign targeting drinking and wastewater sites in at least seven U.S. states.
[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents
Register for an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents Talos IR faced in Q2.
AI Adoption Shifts Focus Toward Data Governance and Enterprise Trust
The rise of artificial intelligence (AI) is uncovering vulnerabilities in enterprise data governance, as organizations grapple with managing information…
TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks
TP-Link has issued a security advisory regarding a high-severity vulnerability affecting its TL-WR940N V6 wireless router. This vulnerability, tracked as…
Russian spies turn public Wi-Fi into malware delivery systems
Keyloggers, audio-visual surveillance, and token theft on CaptivePortal’s agenda as hospitality sector put on alert
Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.
Hugging Face Diffusers Vulnerabilities Enable Remote Code Execution Through Malicious AI Models
A set of high-severity vulnerabilities in Hugging Face’s diffusers library that allow a malicious model repository to silently execute arbitrary code on…
China-based hacker employs DeepSeek in autonomous threat campaign
Researchers said the hacker also attempted to test Western AI tools, but ultimately was forced to revert to manual operations to succeed.
Android RAT Survives Reboots Using Watchdog Services and Boot Receivers
Android users are facing a new remote-access threat that hides behind a fake emergency alert application. The malware, called Octagon, poses as Bahrain’s…
Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion
The payments giant says BioCatch’s behavioral and device intelligence will help financial institutions combat account takeovers, scams and other forms of…
Hackers Exploit VeloCloud Orchestrator Command Injection Vulnerability in the Wild
Security researchers have issued a warning about a critical command injection vulnerability that is being actively exploited in on-premises VeloCloud…
From Threat Intelligence to Action: The First Cybercrime Bounty Is Now Live
Crime Stoppers International launches Operation Silent Vector I, the first live bounty targeting a cybercrime group, as a part of the Crime Stoppers…
Why Bitcoin Businesses Are Moving to Dedicated VPS Infrastructure
A Bitcoin business rarely runs a simple website. Payment processors, exchanges, wallet services, blockchain analytics products and Lightning…
Why Enterprise AI Agents Fail: A Runtime Data Governance Pattern for Reliable Answers
The Failure You Have Probably Already Seen An enterprise AI agent is deployed against production data. It answers the first ten questions confidently and…
Introducing Unit 42 Threat Intelligence: Know What Matters, Understand the Adversary, and Act Faster
Security teams do not need another threat feed. Instead, they need to know which threats matter to their organization, what’s coming, and what they should…
China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day
Chinese actors exploited the critical React2Shell exploit inside a day, while 88% of exploited vulnerabilities in H1 2026 were compromised within 48 hours…
Flock Cameras Blanket Southwest Florida, Sparking Privacy and Safety Backlash
Flock Safety’s automated license plate reader (ALPR) cameras are spreading rapidly across Southwest Florida, with hundreds now installed at intersections,…
River Bank obtained assurances from the attackers that the stolen data in the June attack was deleted
River Bank says hackers deleted data stolen in its June ransomware attack, though the investigation into the incident is still ongoing. River Financial…
Hackers Compromise Organization to Swap Crypto Wallet Address In A Supply Chain Attack
Threat actors exploited a JavaScript file offered by advertising technology firm Adform, and modified it into a browser-side tool that rewrites crypto…
Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)
Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution…
Coldcard Wallet Security Incident Linked to Multi-Million Dollar Bitcoin Theft
There has been a connection between a critical firmware flaw in the Coldcard hardware wallet and one of the largest cryptocurrency thefts of the year,…
Cyber Briefing: 2026.08.03
Organizations face escalating risks from sophisticated stealth loaders, pervasive residential proxy exploitation, ransomware-as-a-service operations like…
Midnight Blizzard Targets Travelers via Captive Portals
Russian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokens
H96 Android TV Boxes Used for Ad Fraud and Residential Proxies
Bitsight found Fuyao software on H96 Android TV boxes, letting operators fake ad clicks and route proxy traffic through their owners’ home internet…