Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger…
CISA sets a new SBOM baseline
The US Cybersecurity and Infrastructure Security Agency (CISA), together with its co-authoring partners, has released the 2026 Minimum Elements for a…
AtlasRAT Uses Four-Stage In-Memory Loader to Keylog and Inject Malware Into WeChat
AtlasRAT is a modular Windows remote access trojan that uses a four-stage, fully in-memory loader chain to quietly establish TLS‑ and ChaCha20‑protected…
Onyx Security Raises $113 Million to Control AI Agents in the Enterprise
The Series B funding round brings the total raised by Onyx Security to $153 million.
Apple Delays First Smart Glasses to WWDC 2027 Over Privacy Concerns
Apple has postponed the reveal of its first smart glasses to WWDC in June 2027, with sales anticipated later that year, according to Bloomberg analyst…
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file.…
‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale
Researchers warn that AI could turn dangling DNS takeovers into a nation-state weapon capable of disrupting governments, banks and global supply chains.
The Network Has Become the Control Plane for AI Security
Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing…
Check Point Brings AI Security into the Firewall with Industry-First AI Network Firewall
Check Point Software has launched what it calls the industry’s first AI Network Firewall, extending AI-specific inspection and control into the firewall…
SpaceX Starship Rocket Splashes Down After Successful Test
Forty-storey-tall Starship vessel carries out sub-orbital flight and splashes down in Indian Ocean in latest test
Nvidia opens AI security tent, Microsoft adds cyber sprinter to MDASH, Fairlife ransomware spills data
Nvidia opens the AI security tent Microsoft puts a cyber sprinter in MDASH Fairlife ransomware spills data Get the show notes here:…
Command Injection Cheatsheet: OS Payloads And Prevention (2026)
OS Command Injection is a critical vulnerability (CWE-78) where an attacker executes arbitrary operating system commands via a…
Orca Security secures AI-built and developer-created applications
Orca Security has announced two new AI-powered capabilities: Orca AI AppGen Security, which discovers and secures AI applications built outside the…
AutoIT Payload Injector , (Tue, Jul 28th)
For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it’s easy to write and powerful. Indeed, it…
CISA Adds Cisco Secure Firewall Management Flaw to Exploited Vulnerabilities List
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Cisco Secure Firewall Management Center (FMC),…
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The…
Shein Sees $99m Loss Ahead Of Hong Kong IPO
China-founded e-commerce company sees US market contract, falls to loss in first quarter as it prepares to list in Hong Kong
Houston City College – 831,642 breached accounts
In June 2026, Houston City College was the target of a ShinyHunters “pay or leak” extortion campaign . Data allegedly obtained from the college was later…
Should You Use AI for a Task? Here’s a Simple Way to Decide
This essay originally appeared in The Guardian . I teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto. And…
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan…
Hugging Face Has a Deepfake Nudes Problem
Researchers tested top image editing models on Hugging Face and found they could easily create explicit deepfakes—and 1,000 image editing prompts show how…
Semiconductor Firm Analog Devices Discloses Data Breach
Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.
Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks
Attackers are moving away from fake Microsoft login pages in favor of abusing Microsoft’s own authentication system, letting phishing campaigns slip past…
Linux XMRig Botnet Abuses PAM for Fileless Monero Mining and Persistent Access
A covert Monero (XMR) cryptomining campaign uncovered in May 2026 is abusing Linux Pluggable Authentication Modules (PAM) to evade detection, maintain…