Mac users are being targeted by a ClickFix campaign that turns a fake verification prompt into a path for malware installation. Victims are persuaded to…
Microsoft Threat Intelligence Portal Retires August 1: 4 Checks Before the Cutoff
Microsoft is retiring its legacy Threat Intelligence portal on August 1. Security teams should verify licenses, permissions, investigation projects, APIs,…
Critical Ruflo MCP Bridge Flaw Lets Attackers Execute Commands and Hijack AI Agents
A critical security flaw in the open-source AI orchestration platform Ruflo has been disclosed, allowing unauthenticated attackers to execute arbitrary…
Building Trustworthy Agentic AI: How Security Concerns Have Changed in 2026
2026 is touted as the year AI moves from speculation and interest to real-world deployment and value. Yet one global analyst firm predicts 40% of agentic…
NVIDIA BlueField Vulnerability Enables Code Execution Attacks
NVIDIA has disclosed a serious vulnerability affecting its BlueField DPUs and ConnectX networking platforms that could allow attackers to execute code on…
MCBS Healthcare Data Breach Affects 1.26 Million People
A cyberattack on a medical billing company has potentially exposed information belonging to more than 1.26 million people, underscoring that healthcare’s…
Hijacked Joyfill npm Packages Deploy Worm-Like RAT and Steal Developer Credentials
A fresh supply chain scare hit software teams after attackers slipped malware into trusted open source libraries. On July 28, 2026, malicious beta builds…
IT Security News Hourly Summary 2026-07-29 18h : 9 posts
9 posts were published in the last hour 16:2 : Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory 16:2 : LogoKit Phishing Kit Screenshots Victim Sites in Real Time 16:2 : Ernst & Young Notifies Clients…
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI…
LogoKit Phishing Kit Screenshots Victim Sites in Real Time
LogoKit now builds per-victim phishing pages using live screenshots of the target’s real website
Ernst & Young Notifies Clients Following Third-Party Support Platform Data Breach
The company Ernst & Young (EY) has sent out notices to the affected clients about the data breach involving the third-party support ticket platform, which…
Google goes it alone with a new cybercrime crew taxonomy
So much for Microsoft and CrowdStrike’s plans for consistent names across the industry
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been…
CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In
Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at…
Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging
Iran infrastructure warning, ChatGPT global outage, self-assembling malware
U.S. agencies warn of Iran-linked actors targeting water and energy control systems ChatGPT suffered brief global outage on Saturday Malvertising sends…
AI robocalls: Why caller ID is still lying to you
AI is making robocall scams cheaper, more convincing, and harder to spot. Here’s why caller ID still isn’t enough.
CVSS 10.0 RufRoot Vulnerability Allowed Attackers to Hijack Ruflo Without Login
Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at…
Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with…
As data breaches grow costlier, ungoverned AI creates new risks
Meanwhile, many companies still aren’t doing the basics to protect on-premises data, IBM found.
Meta AI Bots Drain Publishers With 9 Billion Q2 Requests
Meta’s AI bots are rapidly becoming a costly headache for online publishers, exposing a structural imbalance in how AI platforms use web content. Recent…
Secure your npm and pip package updates in Amazon Linux
If you use and install packages from npm or PyPI, the first hours after a package is published are the riskiest because scanners can’t analyze packages…
Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide…
Cyber Briefing: 2026.07.29
Active zero-day exploitation, massive consumer-facing scams, and recurring enterprise breaches highlight severe operational and financial vulnerabilities…