🔒 Security News Digest - 2026-09-18
📊 18 updates from 6 sources:
🔹 The Hacker News: Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
https://thehackernews.com/2026/09/claimed-bug-bounty-hunter-likely-used.html
🔹 SecurityWeek: Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
https://www.securityweek.com/brevo-supply-chain-attack-injects-malware-into-100000-websites/
🔹 Unit 42: A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity
https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/
🔹 SecurityWeek: NightmareStresser DDoS Service Disrupted in International Operation
https://www.securityweek.com/nightmarestresser-ddos-service-disrupted-in-international-operation/
🔹 The Hacker News: WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html
🔹 SecurityWeek: Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
https://www.securityweek.com/microsoft-patches-18-vulnerabilities-in-ai-cloud-products/
🔹 The Hacker News: Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
https://thehackernews.com/2026/09/plugin4shell-lets-repository-owners.html
🔹 The Hacker News: An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
https://thehackernews.com/2026/09/an-abandoned-cdn-domain-was-re.html
🔹 SecurityWeek: 23 Million User Records Compromised in Gyazo Data Breach
https://www.securityweek.com/23-million-user-records-compromised-in-gyazo-data-breach/
🔹 SecurityWeek: AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
https://www.securityweek.com/ai-built-exploit-and-sign-in-flaw-opened-path-to-internal-openai-code/
🔹 The Hacker News: Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html
🔹 The Record from Recorded Future News: Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia
https://therecord.media/hacking-group-nighteagle-expands-russia-china
🔹 Security News | TechCrunch: Researchers used Anthropic’s Claude to hack into OpenAI
https://techcrunch.com/2026/09/18/researchers-used-anthropics-claude-to-hack-into-openai/
🦠 Malwarebytes: Did an AI really try to break free from human control?
https://www.malwarebytes.com/blog/ai/2026/09/did-an-ai-really-try-to-break-free-from-human-control
🔹 SecurityWeek: In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
https://www.securityweek.com/in-other-news-ransomware-developer-sentenced-plugin4shell-ai-attack-critical-sap-flaw/
🔹 The Record from Recorded Future News: Nations take action on North Korean IT workers after UN report
https://therecord.media/nations-take-action-on-north-korean-it-worker-schemes
🦠 Malwarebytes: New Android malware uses AI to steal bank logins and PINs
https://www.malwarebytes.com/blog/news/2026/09/new-android-malware-uses-ai-to-steal-bank-logins-and-pins
🔹 Security News | TechCrunch: FBI, Coast Guard boarded hacked oil tankers heading towards US coast
https://techcrunch.com/2026/09/18/fbi-coast-guard-boarded-hacked-oil-tankers-heading-towards-us-coast/
#InfoSec #SecurityNews
About This Hashtag
#securitynews
53 posts
Last used 1d
#securitynews
53 posts· Last used 1d
🔒 Security News Digest - 2026-09-09
📊 23 updates from 7 sources:
🔹 The Hacker News: Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html
🔹 The Hacker News: U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
https://thehackernews.com/2026/09/us-agencies-accuse-china-ai-firms-of.html
🔹 SecurityWeek: Chrome 153 Patches Seventh Zero-Day of 2026
https://www.securityweek.com/chrome-153-patches-seventh-zero-day-of-2026/
🔹 SecurityWeek: This Key Will Self-Destruct: An Open Standard for Revocable API Keys
https://www.securityweek.com/this-key-will-self-destruct-an-open-standard-for-revocable-api-keys/
🔹 SecurityWeek: New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser
https://www.securityweek.com/new-phishing-attack-creates-malicious-pages-inside-the-victims-browser/
🔹 Unit 42: Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
🦠 Malwarebytes: Microsoft fixes record 964 flaws, including 2 exploited zero-days
https://www.malwarebytes.com/blog/news/2026/09/microsoft-fixes-record-964-flaws-including-2-exploited-zero-days
🔹 SecurityWeek: Ivanti Patches Critical Flaws Across Enterprise Security Products
https://www.securityweek.com/ivanti-patches-critical-flaws-across-enterprise-security-products/
🔹 The Hacker News: Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html
🔹 SecurityWeek: ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
https://www.securityweek.com/ics-patch-tuesday-schneider-electric-siemens-fix-critical-flaws/
🔹 The Hacker News: DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html
🔹 The Hacker News: Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
https://thehackernews.com/2026/09/webinar-learn-how-to-answer-are-we.html
🔹 SecurityWeek: Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy
https://www.securityweek.com/meta-launches-personal-ai-agent-muse-emphasizes-safety-and-privacy/
🔹 The Record from Recorded Future News: Ukraine prosecutor general steps down amid scam call center bribery probe
https://therecord.media/ukraine-prosecutor-general-scam-center
🔹 SecurityWeek: US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities
https://www.securityweek.com/us-agencies-warn-china-is-systematically-extracting-frontier-ai-capabilities/
🔹 Security News | TechCrunch: Sequoia doubles down on Cymphony as AI agents create new enterprise security risks
https://techcrunch.com/2026/09/09/sequoia-doubles-down-on-cymphony-as-ai-agents-create-new-enterprise-security-risks/
🔹 Security News | TechCrunch: Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms
https://techcrunch.com/2026/09/09/group-of-bipartisan-lawmakers-ask-us-government-to-ban-several-hack-for-hire-firms/
🔹 The Hacker News: Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html
🔹 SecurityWeek: Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
https://www.securityweek.com/fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension/
🔹 darkreading: Identity-Based AI Attack Threatens Security of Enterprise Data
https://www.darkreading.com/threat-intelligence/identity-based-ai-attack-security-enterprise-data
🔹 Security News | TechCrunch: ‘Gambling with our lives’: Anthropic researcher quits, warns against self-improving AI
https://techcrunch.com/2026/09/09/gambling-with-our-lives-anthropic-researcher-quits-warns-against-self-improving-ai/
🦠 Malwarebytes: More than 100,000 fake stores are out to steal your card details
https://www.malwarebytes.com/blog/scams/2026/09/more-than-100000-fake-stores-are-out-to-steal-your-card-details
🔹 The Record from Recorded Future News: FBI puts its cyber strategy on paper
https://therecord.media/fbi-releases-first-public-cybersecurity-strategy
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-08-11
📊 15 updates from 5 sources:
🦠 Malwarebytes: Fake popular sites offer a free app, instead take over PCs
https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-popular-sites-offer-a-free-app-instead-take-over-pcs
🦠 Malwarebytes: Watch out for fake TikTok Shops trying to steal your money
https://www.malwarebytes.com/blog/scams/2026/08/watch-out-for-fake-tiktok-shops-trying-to-steal-your-money
🔹 The Hacker News: Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
https://thehackernews.com/2026/08/gunra-ransomware-exploits-fortinet-and.html
🔹 SecurityWeek: OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber
https://www.securityweek.com/openai-unveils-new-cybersecurity-model-gpt-5-6-cyber/
🔹 SecurityWeek: Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption
https://www.securityweek.com/hacker-conversations-marcus-hutchins/
🔹 Unit 42: Kimwolf v7: An Evolution of the Kimwolf Botnet
https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
🔹 The Hacker News: Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
https://thehackernews.com/2026/08/malicious-mcp-servers-can-split.html
🔹 The Hacker News: Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
https://thehackernews.com/2026/08/researchers-turn-usb-auto-install-into.html
🔹 SecurityWeek: Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities
https://www.securityweek.com/extension-banned-for-stealing-ai-chats-returns-to-chrome-store-resumes-malicious-activities/
🔹 The Hacker News: Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
https://thehackernews.com/2026/08/researchers-built-fake-crypto-startup.html
🔹 SecurityWeek: Corma Raises $60 Million for Defensive Cybersecurity AI Model
https://www.securityweek.com/corma-raises-60-million-for-defensive-cybersecurity-ai-model/
🔹 The Hacker News: Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
https://thehackernews.com/2026/08/mozilla-revokes-firefox-and-thunderbird.html
🔹 The Hacker News: A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html
🔹 The Record from Recorded Future News: Kids’ online safety bill faces dim prospects of passage this session despite progress
https://therecord.media/kids-online-safety-act-congress
🦠 Malwarebytes: Love/hate relationship: The AI affair. Young people love AI, but it’s breaking their trust
https://www.malwarebytes.com/blog/ai/2026/08/love-hate-relationship-the-ai-affair-young-people-love-ai-but-its-breaking-their-trust
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-08-06
📊 5 updates from 3 sources:
🔹 darkreading: No Perfect Fix for AI Browser Prompt Injection Flaws
https://www.darkreading.com/application-security/no-perfect-fix-ai-browser-prompt-injection-flaws
🔹 Latest Bulletins: CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server
https://aws.amazon.com/security/security-bulletins/rss/2026-076-aws/
🔹 darkreading: AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
https://www.darkreading.com/cyber-risk/ai-browsers-zero-click-agent-hijacking
🔹 darkreading: AI Sends Global Crime Syndicates Into Fraud Nirvana
https://www.darkreading.com/threat-intelligence/ai-global-crime-syndicates-fraud-nirvana
🔹 Have I Been Pwned latest breaches: Inter-Con Security - 276,114 breached accounts
https://haveibeenpwned.com/Breach/InterConSecurity
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-08-04
📊 7 updates from 5 sources:
🔹 Latest Bulletins: CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation
https://aws.amazon.com/security/security-bulletins/rss/2026-073-aws/
🔹 darkreading: Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
https://www.darkreading.com/cyberattacks-data-breaches/latest-rmm-fueled-phishing-attack-exposes-threat-actor-playbook
🔹 Security News | TechCrunch: Nvidia doesn’t mess around: A week after open AI industry group formed, it’s already showing progress
https://techcrunch.com/2026/08/04/nvidia-doesnt-mess-around-a-week-after-open-ai-industry-group-formed-its-already-showing-progress/
🔹 Latest Bulletins: CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows
https://aws.amazon.com/security/security-bulletins/rss/2026-074-aws/
🔹 The Record from Recorded Future News: OpenAI: Cambodian scam centers used ChatGPT to lure Indian nationals, conduct investment fraud
https://therecord.media/openai-chatgpt-cambodia-scam-centers-disruption
🔹 Security News | TechCrunch: Android app developers may be unwittingly sharing their users’ location data with advertisers
https://techcrunch.com/2026/08/04/android-app-developers-may-be-unwittingly-sharing-their-users-location-data-with-advertisers/
🦠 Malwarebytes: Apple battles it out again with the UK over encrypted iCloud access
https://www.malwarebytes.com/blog/news/2026/08/apple-battles-it-out-again-with-uk-over-encrypted-icloud-access
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-08-04
📊 15 updates from 6 sources:
🔹 The Hacker News: New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html
🔹 SecurityWeek: Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering
https://www.securityweek.com/gemini-agent-to-agent-attack-exposed-secrets-enabled-pull-request-tampering/
🔹 The Hacker News: Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html
🔹 The Hacker News: When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted
https://thehackernews.com/2026/08/when-vibe-hacking-turns-ai-into-junior.html
🦠 Malwarebytes: Online backlash ends in Google rolling back Google Earth AI tool after a day
https://www.malwarebytes.com/blog/news/2026/08/online-backlash-ends-in-google-rolling-back-google-earth-ai-tool-after-a-day
🔹 SecurityWeek: TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover
https://www.securityweek.com/tp-link-omada-ztp-vulnerabilities-chain-into-full-network-takeover/
🔹 SecurityWeek: Obsidian Security Raises $85 Million at $1.1 Billion Valuation
https://www.securityweek.com/obsidian-security-raises-85-million-at-1-1-billion-valuation/
🦠 Malwarebytes: Travelers targeted when logging into hotel Wi-Fi networks
https://www.malwarebytes.com/blog/news/2026/08/travelers-targeted-when-logging-into-hotel-wi-fi-networks
🔹 The Record from Recorded Future News: Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected
https://therecord.media/swiss-bit-foitt-hacked-possibly-sharepoint-vulnerabilities
🔹 Unit 42: Almost Half of Malware Samples Communicate Direct to IP
https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/
🔹 darkreading: AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
https://www.darkreading.com/application-security/ai-notetaker-spy-government-corporate-video-calls
🔹 The Record from Recorded Future News: Apple launches new legal challenge against UK over iCloud access
https://therecord.media/apple-uk-tcn-icloud-new-legal-challenge
🔹 Unit 42: The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software
https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/
🔹 SecurityWeek: Zenity Raises $125 Million in Series C Funding
https://www.securityweek.com/zenity-raises-125-million-in-series-c-funding/
🔹 SecurityWeek: Weaponized Email AI Assistants Could Help Attackers Hijack Accounts
https://www.securityweek.com/weaponized-email-ai-assistants-could-help-attackers-hijack-accounts/
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-08-04
📊 5 updates from 3 sources:
🔹 darkreading: Device Code Phishing Up 1,500% in 2026; Vishing Doubles
https://www.darkreading.com/cybersecurity-analytics/device-code-phishing-vishing-doubles
🔹 The Hacker News: CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
https://thehackernews.com/2026/08/cisa-adds-exploited-n-able-n-central.html
🔹 SecurityWeek: 150,000 Impacted by Madera Community Hospital Data Breach
https://www.securityweek.com/150000-impacted-by-madera-community-hospital-data-breach/
🔹 The Hacker News: DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html
🔹 SecurityWeek: Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
https://www.securityweek.com/decades-old-bmc-vulnerability-exposes-thousands-of-data-centers-to-attacks/
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-08-03
📊 6 updates from 4 sources:
🔹 SecurityWeek: Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion
https://www.securityweek.com/visa-to-acquire-fraud-intelligence-firm-biocatch-for-2-4-billion/
🔹 darkreading: Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm
https://www.darkreading.com/cyberattacks-data-breaches/chinese-actor-deepseek-ai-agent-attack-security-firm
🔹 SecurityWeek: Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)
https://www.securityweek.com/black-hat-usa-2026-summary-of-vendor-announcements-part-1/
🔹 The Hacker News: INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
🔹 The Hacker News: Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
https://thehackernews.com/2026/08/google-password-manager-attacks-could.html
🔹 The Record from Recorded Future News: Hackers steal 31,000 records identifying people behind Liechtenstein companies, foundations
https://therecord.media/hackers-steal-records-liechtenstein-companies-foundations
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-08-03
📊 10 updates from 4 sources:
🔹 The Hacker News: Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
https://thehackernews.com/2026/08/hugging-face-diffusers-flaws-could-let.html
🔹 The Hacker News: N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html
🦠 Malwarebytes: A week in security (July 27 – August 2)
https://www.malwarebytes.com/blog/news/2026/08/a-week-in-security-july-27-august-2
🔹 The Hacker News: Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-could.html
🔹 SecurityWeek: US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States
https://www.securityweek.com/us-water-cyberattacks-extend-beyond-minnesota-to-at-least-6-other-states/
🔹 The Hacker News: PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html
🔹 SecurityWeek: Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
https://www.securityweek.com/russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking/
🔹 Unit 42: Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/
🔹 SecurityWeek: Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
https://www.securityweek.com/recent-sonicwall-vulnerabilities-exploited-in-ransomware-attacks/
🔹 The Hacker News: Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-31
📊 7 updates from 4 sources:
🦠 Malwarebytes: Fake Flash Player installs AtlasRAT
https://www.malwarebytes.com/blog/news/2026/07/fake-flash-player-installs-atlasrat
🔹 The Hacker News: Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html
🔹 The Hacker News: 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
https://thehackernews.com/2026/07/6-reasons-why-device-code-phishing-is.html
🔹 The Record from Recorded Future News: Anthropic says its AI hacked real-world companies in three incidents
https://therecord.media/anthropic-ai-hacked-three-real-companies
🔹 darkreading: USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports
https://www.darkreading.com/identity-access-management-security/usa-fencing-hidden-identity-challenge-amateur-sports
🔹 darkreading: DROP Platform Lets Californians Reduce Digital Footprint
https://www.darkreading.com/data-privacy/drop-platform-lets-californians-ditch-their-data
🔹 darkreading: Interpol Leverages Global System to Curtail Fraud Payments
https://www.darkreading.com/cybersecurity-operations/interpol-leverages-global-system-curtail-fraud-payments
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-31
📊 6 updates from 2 sources:
🔹 SecurityWeek: Critical Code Execution Vulnerability Patched in TeamCity
https://www.securityweek.com/critical-code-execution-vulnerability-patched-in-teamcity/
🔹 SecurityWeek: CareCloud Data Breach Impacts Over 350,000
https://www.securityweek.com/carecloud-data-breach-impacts-over-350000/
🔹 SecurityWeek: Critical Flaw Led to Azure Cosmos DB Pwnage
https://www.securityweek.com/critical-flaw-led-to-azure-cosmos-db-pwnage/
🔹 SecurityWeek: Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations
https://www.securityweek.com/after-openai-disclosure-anthropic-finds-its-own-models-hacked-3-organizations/
🔹 Unit 42: The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/
🔹 SecurityWeek: Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace
https://www.securityweek.com/googles-ai-agent-uncovers-13-year-old-chrome-flaw-amid-record-patching-pace/
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-30
📊 7 updates from 5 sources:
🔹 The Hacker News: DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html
🔹 Security News | TechCrunch: Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI
https://techcrunch.com/2026/07/30/google-says-it-fixed-more-chrome-bugs-in-june-than-over-the-past-two-years-thanks-to-ai/
🔹 The Record from Recorded Future News: Semiconductor chip titan Analog Devices reports data breach
https://therecord.media/analog-devices-semiconductor-company-data-breach
🔹 SecurityWeek: Okta to Acquire Identity Threat Detection Firm Permiso
https://www.securityweek.com/okta-to-acquire-identity-threat-detection-firm-permiso/
🔹 darkreading: AI Harnesses Burst With Potential Exploit Opps
https://www.darkreading.com/application-security/ai-harnesses-potential-exploit-opps
🔹 Security News | TechCrunch: CareCloud begins to notify hundreds of thousands after hackers stole medical records
https://techcrunch.com/2026/07/30/carecloud-begins-to-notify-hundreds-of-thousands-after-hackers-stole-medical-records/
🔹 SecurityWeek: Bank of America to Acquire Cybersecurity Firm MDSec
https://www.securityweek.com/bank-of-america-to-acquire-cybersecurity-firm-mdsec/
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-30
📊 11 updates from 8 sources:
🦠 Malwarebytes: Hims & Hers sued over alleged health data privacy failures
https://www.malwarebytes.com/blog/privacy/2026/07/hims-hers-sued-over-alleged-health-data-privacy-failures
🔹 Threat Intelligence: Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise
https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise/
🔹 SecurityWeek: DataBahn Raises $40 Million for Agentic Data Pipeline Management
https://www.securityweek.com/databahn-raises-40-million-for-agentic-data-pipeline-management/
🔹 The Record from Recorded Future News: North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
https://therecord.media/north-korea-hackers-ransomware
🔹 Security News | TechCrunch: In the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppable
https://techcrunch.com/2026/07/30/in-the-hugging-face-breach-openais-hacker-was-noisy-and-fast-but-not-unstoppable/
🔹 The Hacker News: ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html
🔹 darkreading: Claude Mythos — Hype vs. Reality: What Security Teams Need to Know
https://www.darkreading.com/cybersecurity-operations/claude-mythos-hype-vs-reality
🔹 SecurityWeek: Timeless Compliance: Why Better Questions Beat Bigger Frameworks
https://www.securityweek.com/timeless-compliance-why-better-questions-beat-bigger-frameworks/
🦠 Malwarebytes: Malwarebytes for Windows, now available on the Microsoft Store
https://www.malwarebytes.com/blog/product/2026/07/malwarebytes-for-windows-now-available-on-the-microsoft-store
🔹 Security News | TechCrunch: Okta buys AI security startup Permiso; source says for about $200M
https://techcrunch.com/2026/07/30/okta-buys-ai-security-startup-permiso-source-says-for-about-200m/
🔹 Krebs on Security: Read This Before You Buy That TV Streaming Stick
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-30
📊 8 updates from 3 sources:
🔹 SecurityWeek: Cisco Secure FMC Zero-Day Exploited in the Wild
https://www.securityweek.com/cisco-secure-fmc-zero-day-exploited-in-the-wild/
🔹 The Hacker News: FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
https://thehackernews.com/2026/07/fcc-blocks-new-foreign-produced-robots.html
🔹 The Hacker News: Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html
🔹 SecurityWeek: Chrome 151 Patches 370 Vulnerabilities
https://www.securityweek.com/chrome-151-patches-370-vulnerabilities/
🔹 SecurityWeek: US and Allies Update SBOM Guidance
https://www.securityweek.com/us-and-allies-update-sbom-guidance/
🔹 SecurityWeek: 1 in 5 Data Center Assets Are Within Easy Reach of Attackers
https://www.securityweek.com/1-in-5-data-center-assets-are-within-easy-reach-of-attackers/
🔹 SecurityWeek: Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms
https://www.securityweek.com/critical-ruflo-flaw-lets-attackers-spawn-rogue-ai-swarms/
🔹 Unit 42: Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-29
📊 7 updates from 4 sources:
🔹 The Record from Recorded Future News: OpenAI says rogue agent behind Hugging Face hack broke into additional services
https://therecord.media/openai-says-rogue-agent-behind-hugging-face-hack-broke-into-additional-services
🔹 darkreading: Hugging Face Hack Lessons for Cyber Defenders
https://www.darkreading.com/cyberattacks-data-breaches/hugging-face-hack-lessons-cyber-defenders
🔹 Security News | TechCrunch: US government bans new foreign-made humanoids, robot dogs, and solar inverters, citing risks to national security
https://techcrunch.com/2026/07/29/us-government-bans-new-foreign-made-humanoids-robot-dogs-and-solar-inverters-citing-risks-to-national-security/
🔹 darkreading: Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions
https://www.darkreading.com/cyberattacks-data-breaches/liable-ai-agents-escape-hugging-face-breach-questions
🔹 The Hacker News: Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
🔹 darkreading: Red Agents vs. Blue Agents: How to Make AI Better At Defense
https://www.darkreading.com/cybersecurity-operations/red-agents-vs-blue-agents-make-ai-better-defense
🔹 darkreading: OpenAI Rogue AI Incident Hit More Services Than Initially Thought
https://www.darkreading.com/application-security/openai-rogue-ai-incident-services-initially-thought
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-29
📊 8 updates from 2 sources:
🔹 The Hacker News: Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html
🔹 The Hacker News: New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html
🔹 The Hacker News: OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
https://thehackernews.com/2026/07/openai-agent-used-exposed-credentials.html
🔹 SecurityWeek: Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
https://www.securityweek.com/dozens-of-minnesota-water-utilities-targeted-in-coordinated-ot-attacks/
🔹 SecurityWeek: JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
https://www.securityweek.com/jfrog-zero-days-exploited-in-openai-hugging-face-hack/
🔹 The Hacker News: Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html
🔹 SecurityWeek: Spur Raises $200 Million for IP Intelligence Platform
https://www.securityweek.com/spur-raises-200-million-for-ip-intelligence-platform/
🔹 SecurityWeek: OpenAI’s Rogue AI Ventured Beyond Hugging Face
https://www.securityweek.com/openais-rogue-ai-ventured-beyond-hugging-face/
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-29
📊 6 updates from 4 sources:
🔹 darkreading: Thousands of Data Center Controllers Open to Takeover
https://www.darkreading.com/cyber-risk/flaw-exposes-data-centers-server-takeover
🔹 darkreading: Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
https://www.darkreading.com/cloud-security/non-human-identity-sprawl-creates-a-new-cloud-attack-path
🔹 The Record from Recorded Future News: Senate confirms Clayton as intel chief after delays
https://therecord.media/jay-clayton-confirmed-dni-senate
🔹 Security News | TechCrunch: Cyera agrees to acquire Oasis Security for $1B to safeguard proliferating AI agents
https://techcrunch.com/2026/07/28/cyera-agrees-to-acquire-oasis-security-for-1b-to-safeguard-proliferating-ai-agents/
🔹 iTnews - Security: Okta details 'Work Panel', a turnkey SaaS platform for vishing crews
https://www.itnews.com.au/news/okta-details-work-panel-a-turnkey-saas-platform-for-vishing-crews-627745?utm_source=feed&utm_medium=rss&utm_campaign=iTnews+Security+feed
🔹 iTnews - Security: OpenAI's Hugging Face hack mixed technical brilliance with incoherent noise
https://www.itnews.com.au/news/openais-hugging-face-hack-mixed-technical-brilliance-with-incoherent-noise-627749?utm_source=feed&utm_medium=rss&utm_campaign=iTnews+Security+feed
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-28
📊 6 updates from 2 sources:
🔹 SecurityWeek: Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
https://www.securityweek.com/critical-arista-velocloud-orchestrator-vulnerability-exploited-as-zero-day/
🔹 SecurityWeek: Unpatched Fastjson Vulnerability Exploited in Attacks
https://www.securityweek.com/unpatched-fastjson-vulnerability-exploited-in-attacks/
🔹 The Hacker News: Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
https://thehackernews.com/2026/07/researcher-says-ai-helped-develop-linux.html
🔹 The Hacker News: Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
https://thehackernews.com/2026/07/critical-teamcity-flaw-could-let.html
🔹 SecurityWeek: Google Adopts New Threat Actor Naming System
https://www.securityweek.com/google-adopts-new-threat-actor-naming-system/
🔹 SecurityWeek: Hush Security Raises $30 Million for AI Agent Governance
https://www.securityweek.com/hush-security-raises-30-million-for-ai-agent-governance/
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-27
📊 8 updates from 6 sources:
🔹 The Record from Recorded Future News: UK court rejects Bahrain immunity claim in spyware case
https://therecord.media/uk-court-rejects-bahrain-immunity-claim-spyware-case
🔹 The Hacker News: NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
https://thehackernews.com/2026/07/nvidia-forms-37-member-open-secure-ai.html
🔹 Security News | TechCrunch: Microsoft launches its first cybersecurity model, plus a new agentic cybersecurity system
https://techcrunch.com/2026/07/27/microsoft-launches-its-first-cyber-model-and-a-new-agentic-cybersecurity-system/
🦠 Malwarebytes: Aftercall ads are driving Android users crazy
https://www.malwarebytes.com/blog/news/2026/07/aftercall-ads-are-driving-android-users-crazy
🔹 Security News | TechCrunch: PSA: Your Claude shared chats and Artifacts may have ended up on Google
https://techcrunch.com/2026/07/27/psa-your-claude-shared-chats-and-artifacts-may-have-ended-up-on-google/
🔹 darkreading: FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
https://www.darkreading.com/cybersecurity-operations/fbi-breaking-affiliate-trust-lockbit-takedown
🔹 iTnews - Security: ASD to critical infrastructure ops: be ready to isolate systems for three months
https://www.itnews.com.au/news/asd-to-critical-infrastructure-ops-be-ready-to-isolate-systems-for-three-months-627708?utm_source=feed&utm_medium=rss&utm_campaign=iTnews+Security+feed
🔹 The Record from Recorded Future News: Outdated VPNs should be purged from federal agencies, senator says
https://therecord.media/federal-purge-outdated-vpns-wyden-letter
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-27
📊 5 updates from 4 sources:
🔹 SecurityWeek: New GitHub, PyPI Policies Boost Supply Chain Security
https://www.securityweek.com/new-github-pypi-policies-boost-supply-chain-security/
🦠 Malwarebytes: What’s your data worth on the dark web? (Lock and Code S07E15)
https://www.malwarebytes.com/blog/podcast/2026/07/whats-your-data-worth-on-the-dark-web-lock-and-code-s07e15
🔹 The Hacker News: Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
https://thehackernews.com/2026/07/public-exploit-released-for-patched.html
🦠 Malwarebytes: Sextortion scammers are exploiting ShinyHunters data leaks
https://www.malwarebytes.com/blog/scams/2026/07/sextortion-scammers-are-exploiting-shinyhunters-data-leaks
🔹 The Record from Recorded Future News: Telegram phishing campaign targeted exiled Belarusian activist, Russians and Kazakhstanis
https://therecord.media/telegram-belarus-activist-russia-cyberattack
#InfoSec #SecurityNews