Fitness trackers have become part of everyday life, helping people monitor steps, sleep, heart rate, stress, and workouts with impressive convenience. But…
SSH Bot Profiles Linux CPU, GPU and RAM Before Deploying Cryptocurrency Miner
A new SSH bot has been caught quietly logging into Linux systems, profiling their CPU, GPU, and memory, and then walking away without dropping any visible…
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI…
DeepSeek-Powered Hermes Agent Launches Autonomous Cyberattacks Against Exposed Servers
A Chinese-speaking threat actor used an AI-driven agent to search for vulnerable internet-facing servers and begin attacks with little direct human input.…
Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging
ShutterGap Exposes Millions of AWS Resources Between Cloud Security Scans
Cloud security teams often utilize Cloud Security Posture Management (CSPM) and Cloud-Native Application Protection Platform (CNAPP) tools to identify…
Ernst & Young Notifies Clients Following Third-Party Support Platform Data Breach
The company Ernst & Young (EY) has sent out notices to the affected clients about the data breach involving the third-party support ticket platform, which…
CMMC Phase II Is Paused, But Contractors’ Data-Security Obligations Are Not
By John Grancarich, EVP, Head of Defense & Intelligence, Fortra The recent pause affecting the implementation of Cybersecurity Maturity Model…
Cyber Briefing: 2026.07.29
Active zero-day exploitation, massive consumer-facing scams, and recurring enterprise breaches highlight severe operational and financial vulnerabilities…
Enterprise ERP AI Adoption Outpaces Security Readiness
A new Onapsis report finds AI adoption across ERP systems is outpacing security readiness.
As data breaches grow costlier, ungoverned AI creates new risks
Meanwhile, many companies still aren’t doing the basics to protect on-premises data, IBM found.
Critical Flaw Allowed to Azure Cosmos DB Pwnage
Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access.
Secure your npm and pip package updates in Amazon Linux
If you use and install packages from npm or PyPI, the first hours after a package is published are the riskiest because scanners can’t analyze packages…
FBI And Allies Warn of North Korean IT Workers Using Stolen Identities
The U.S. State Department, FBI, and allied governments including Japan, Canada, Germany, Australia, the United Kingdom, and the Republic of Korea have…
Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide…
AI robocalls: Why caller ID is still lying to you
AI is making robocall scams cheaper, more convincing, and harder to spot. Here’s why caller ID still isn’t enough.
Google AI Supercharges Chrome Security, Fixing 1,072 Bugs
Google says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google’s…
North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials
A North Korean-linked cyber campaign is using fake macOS update screens to trick victims into installing malware. The operation targets cryptocurrency…
Meta AI Bots Drain Publishers With 9 Billion Q2 Requests
Meta’s AI bots are rapidly becoming a costly headache for online publishers, exposing a structural imbalance in how AI platforms use web content. Recent…
Google Uses AI Agents to Find and Fix 1,072 Chrome Security Vulnerabilities
Google is expanding the use of artificial intelligence (AI) agents across the Chrome security lifecycle to identify source code weaknesses, test patches,…
AI-Speed Attacks and Critical Flaws Compress Defenders’ Response Window this Week of July 2026
Weekly summary of Cybersecurity Insider newsletters
BlackTech APT Deploys BlueShell Linux Backdoor Against Japanese Organizations
BlackTech has been linked to a newly examined Linux backdoor deployment against organizations in Japan, showing how a familiar remote-access tool can be…
Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with…
Critical JetBrains Flaw Allows Attackers to Execute Malicious Code Remotely – Update Now
JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077. This vulnerability allows attackers to bypass…