Attackers broke into an organization’s Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation…
Meta AI Hacked External Systems During Cybersecurity Testing
The incident involved a testing environment set up by Irregular, similar to what Anthropic reported last week.
Hassabis Steps Down As Google DeepMind Chief Amid Major AI Shift
At least four senior AI researchers leave Google to form start-up, while DeepMind head Demis Hassabis hands over operations role at lab
Cisco Patches Multiple Critical Cisco IOS XE Software Vulnerabilities – Patch Now!
Cisco has released a critical security hardening update for Cisco IOS XE Software, fixing several serious vulnerabilities that could expose enterprise…
U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a JetBrains TeamCity vulnerability to its Known Exploited Vulnerabilities catalog. The…
NVIDIA Group Proposes SAFE Initiative for Agentic Threat Intel Sharing
The Open Secure AI Alliance has announced plans for the Shared AI Findings Exchange (SAFE)
Syrian migrant smugglers arrested in coordinated strike in Germany and Serbia
This follows several years of intensive and extensive investigations led by the German Federal Police under the direction of three Bavarian Public…
Meta Previews First AI Coding Agent
Meta launches test version of Muse Code and Muse Spark 1.2, as it looks to compete with Anthropic and OpenAI
Cisco Patches 7 IOS XE Vulnerability Classes, Including Critical Command Injection Flaws
Cisco has released security-hardening updates for IOS XE Software that address seven classes of vulnerabilities, including a critical command, operating…
Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service
A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the…
Photos: Black Hat USA 2026 Arsenal
This week Help Net Security is at the Mandalay Bay, where Arsenal is running alongside the Briefings. If you’ve never been, it’s the corner of Black Hat…
Uber, Wayve Granted First London Robotaxi Licences
Transport for London issues first minicab licences for automated vehicles in capital, though human safety drivers must remain for now
Hackers Turn Ethereum Smart Contract Into Dead-Drop Resolver for Remus Malware
Hackers are abusing an Ethereum smart contract as a dead‑drop resolver to dynamically steer victims’ browsers to rotating command‑and‑control (C2)…
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S.…
OpenAI Agents Worked Together to Find Exploits and Hack External Systems
OpenAI has revealed new details about an incident involving AI agents, in which multiple autonomous agents reportedly worked together to identify…
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Cybersecurity researchers have disclosed details of a “factory-shipped backdoor” implanted in at least 20 Chinese router models from Zbtlink. According to…
Canadian Hacker Pleads Guilty to Stealing Billions of Records From 165 Cloud Customers
Connor Riley Moucka, a 26-year-old Canadian national from Kitchener, Ontario, has pleaded guilty to charges related to a large-scale cloud data theft and…
AI safety tests reach the internet, Private Relay flaw unmasks IPs, weak telcos invite Salt Typhoon
AI safety tests spill onto the real internet Private Relay flaw unmasks IP addresses Weak telcos left door open for Salt Typhoon Get the show notes here:…
CISA Alerts Issues on Actively Exploited TeamCity Remote Code Execution Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in JetBrains TeamCity, tracked as CVE-2026-63077, to…
Microsoft Links Hotel Wi-Fi Attacks Stealing Microsoft 365 Accounts to Russian Hackers
Microsoft has attributed a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard (APT29). Thank you for being…
Explosives-Laden Drone Found At German Airport
Quadcopter fitted with explosive device defused after being found near Ukrainian cargo jet at major air freight hub in Leipzig
Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities
Patches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code.
ICO Reprimands Met Police After Data Leaks
Data protection regulator tells Met to do more, after officer accidentally sends contact details of stalking victim to defendant
New npm Supply Chain Attack Began with the Keyv Library Compromised Hundreds of Popular Packages
A new npm supply chain attack has turned trusted software packages into a route for credential theft. The campaign began after attackers compromised the…