For most CISOs and risk management teams, the concept of exposure management conjures up images of a dashboard…
Fake N26 Support Calls Deploy Copybara Android RAT to Control Banking Apps
A new fraud campaign is targeting Android banking users through convincing phone calls that impersonate N26 support staff. The attack begins as voice…
U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited…
Home Assistant FFmpeg Flaw Lets Attackers Steal Supervisor Tokens and Execute Code as Root
Home Assistant’s FFmpeg integration recently came under scrutiny after researchers demonstrated that unsafe argument handling in the Wyoming Assist…
Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms
Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container.
Black Hat special: Rewind and revisit
Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence.
AI Scammers Are Better at Building Trust Than Humans
Researchers pitted a person against a Claude agent and found that, after a week of texting, the AI chatbot was more effective at creating “exploitable…
PwC Papers Found Riddled With AI Hallucinations
Study finds four papers published by PwC include unverifiable or false claims and citations of unrelated sources
Node.js Fixes 11 Security Flaws That Can Crash Servers and Break Filesystem Restrictions
The Node.js project has released important security updates addressing 11 vulnerabilities across its active branches: 22.x, 24.x, and 26.x. The updates…
eBay, Former Executives Pay $56m To Settle Harassment Case
eBay, several former executives pay total of nearly $50m, with additional contributions to charities, over bizarre harassment campaign
Developer Claims Claude Opus 5 Wiped an Entire Production Database in Minutes
A developer has reported that Anthropic’s Claude Opus 5, running in Ultracode mode, accidentally wiped an entire production database in roughly ten…
Inside the Cybercrime Platform That Turns Helpdesk Calls Into Enterprise Account Takeovers
Voice phishing is no longer limited to a convincing phone call and a fake sign-in page. A newly examined criminal platform called Work Panel brings target…
GitLab Fixes 13 Security Flaws That Can Leak Data, Alter Pipelines, and Crash Servers
GitLab has released critical security updates to address 13 vulnerabilities that could potentially expose sensitive data, manipulate CI/CD pipelines, and…
Google Releases Patches for 370 Vulnerabilities in Chrome 151
The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flaws
Claude Worldwide Outage Disrupts Users With “Request Failed With 529 Overloaded” Message
Anthropic’s Claude AI platform suffered a worldwide outage on July 29, 2026, causing failed prompts, slow responses, interrupted conversations, and…
1 in 5 Data Center Assets Are Within Easy Reach of Attackers
Claroty has analyzed 750,000 cyber-physical systems across some of the world’s largest data center facilities.
Linux Cryptomining Campaign Weaponizes PAM to Hide XMRig Botnet Activity
A new Linux cryptomining campaign has surfaced using a rare trick to stay hidden inside compromised networks. Instead of behaving like typical malware,…
Coordinated cyberattack hits more than 30 Minnesota water utilities
A coordinated cyberattack on July 26 and 27 hit operational technology (OT) systems at more than 30 community water utilities across Minnesota, prompting…
A Two-Minute Microsoft Teams Call Could End With Your Network Encrypted With Ransomware
A short Microsoft Teams call can now become the first step in a ransomware attack. Attackers posing as IT support staff are persuading employees to grant…
eSIM Plus and Nicegram Share Belarus-Linked Codebase, Analysis Finds
Analysis found eSIM Plus and Nicegram share a Belarus-linked codebase, while eSIM Plus routes data and calls through Russian services. Two popular apps…
Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy Chaos Ransomware
Hackers are abusing Microsoft Teams voice calls and fake IT helpdesk personas to gain remote access to corporate endpoints, drop a custom…
NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Devices
The UK’s National Cyber Security Centre wants network device makers to improve forensic observability
Russia Issues Arrest Warrant For Telegram’s Durov
Telegram allegedly used by Ukrainian security services to recruit Russians to carry out sabotage, Russian authorities say
Rogue OpenAI Agents Breached Four Third-Party Services
Out-of-control AI models accessed four third-party services in addition to hacking Hugging Face, OpenAI says