Security Feed
securityfeed@infosec.exchange
<p>Monitors security RSS feeds</p>
Posts
-
Post #4499594
π Security News Digest - 2026-08-11 π 15 updates from 5 sources: π¦ Malwarebytes: Fake popular sites offer a free app, instead take over PCs https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-popular-sites-offer-a-free-app-instead-take-over-pcs π¦ Malwarebytes: Watch out for fake TikTok Shops trying to steal your money https://www.malwarebytes.com/blog/scams/2026/08/watch-out-for-fake-tiktok-shops-trying-to-steal-your-money πΉ The Hacker News: Gunra Ransomware Exploits Fortinet a...
-
Post #4493648
πΉ The Hacker News Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still active inside the network, and customers lost neither...
-
Post #4493645
πΉ SecurityWeek Mozilla Issues New Firefox GPG Key Following Exposure The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek. π https://www.securityweek.com/mozilla-issues-new-firefox-gpg-key-following-exposure/
-
Post #4483950
πΉ The Hacker News OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity. In response to the discovery, the AI upstart said it's implementing security controls for higher-capability models and associated activ...
-
Post #4483949
πΉ The Hacker News Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below - helper-beeps.solidity-pro web3devtoolsx.solidity-pro Although neither of the extensions is now available on Open VSX, the GitHub repository...
-
Post #4483947
π¦ Malwarebytes A week in security (August 3 β August 9) A list of topics we covered in the week of August 3 to August 9 of 2026 π https://www.malwarebytes.com/blog/news/2026/08/a-week-in-security-august-3-august-9
-
Post #4478658
πΉ SecurityWeek Critical Flaws Discovered in Belgian eID Software Used by 2 Million People The vulnerabilities affected software used by eight of Belgiumβs ten largest banks and over 60 government agencies. The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on SecurityWeek. π https://www.securityweek.com/critical-flaws-discovered-in-belgian-eid-software-used-by-2-million-people/
-
Post #4427853
πΉ The Hacker News TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain. "The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend infrastruc...
-
Post #4402402
π Security News Digest - 2026-08-06 π 5 updates from 3 sources: πΉ darkreading: No Perfect Fix for AI Browser Prompt Injection Flaws https://www.darkreading.com/application-security/no-perfect-fix-ai-browser-prompt-injection-flaws πΉ Latest Bulletins: CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server https://aws.amazon.com/security/security-bulletins/rss/2026-076-aws/ πΉ darkreading: AI Browsers Vulnerable to 'PleaseFix&...
-
Post #4391061
πΉ iTnews - Security Anthropic's Mythos 5 targeted real developers in UK cyber test Model without safety filters tried to social engineer coder during test. π https://www.itnews.com.au/news/anthropics-mythos-5-targeted-real-developers-in-uk-cyber-test-627952?utm_source=feed&utm_medium=rss&utm_campaign=iTnews+Security+feed
-
Post #4387923
πΉ iTnews - Security iTnews Executive Retreat &#8211; Security Leaders Edition Hunter Valley, 17&#8211;18 September π https://www.itnews.com.au/feature/itnews-executive-retreat-security-leaders-edition-627912?utm_source=feed&utm_medium=rss&utm_campaign=iTnews+Security+feed
-
Post #4383229
π Security News Digest - 2026-08-04 π 7 updates from 5 sources: πΉ Latest Bulletins: CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness β Insufficient Input Validation https://aws.amazon.com/security/security-bulletins/rss/2026-073-aws/ πΉ darkreading: Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook https://www.darkreading.com/cyberattacks-data-breaches/latest-rmm-fueled-phishing-attack-exposes-threat-actor-playbook πΉ Security News | TechCrunch: Nvidia doesnβt me...
-
Post #4376894
π Security News Digest - 2026-08-04 π 15 updates from 6 sources: πΉ The Hacker News: New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html πΉ SecurityWeek: Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering https://www.securityweek.com/gemini-agent-to-agent-attack-exposed-secrets-enabled-pull-request-tampering/ πΉ The Hacker News: Google Deletes 3 ADK AI Workf...
-
Post #4372580
π Security News Digest - 2026-08-04 π 5 updates from 3 sources: πΉ darkreading: Device Code Phishing Up 1,500% in 2026; Vishing Doubles https://www.darkreading.com/cybersecurity-analytics/device-code-phishing-vishing-doubles πΉ The Hacker News: CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises https://thehackernews.com/2026/08/cisa-adds-exploited-n-able-n-central.html πΉ SecurityWeek: 150,000 Impacted by Madera Community Hospital Data Breach https://www.securi...
-
Post #4368577
πΉ SecurityWeek New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure. The post New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems appeared first on SecurityWeek. π https://www.securityweek.com/new-york-awards-9-million-to-strengthen-cybersecurity-at-153-water-systems/
-
Post #4368574
πΉ darkreading Attackers Exploit N-able Patch Bypass Flaw on RMM Servers Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access. π https://www.darkreading.com/vulnerabilities-threats/attackers-exploit-n-able-patch-bypass-flaw
-
Post #4368573
π¦ Malwarebytes The AI Act kicks into action, forces companies to be clear about AI chatbots The European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumerβfacing AI. π https://www.malwarebytes.com/blog/news/2026/08/the-ai-act-kicks-into-action-forces-companies-to-be-clear-about-ai-bots
-
Post #4361037
π Security News Digest - 2026-08-03 π 6 updates from 4 sources: πΉ SecurityWeek: Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion https://www.securityweek.com/visa-to-acquire-fraud-intelligence-firm-biocatch-for-2-4-billion/ πΉ darkreading: Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm https://www.darkreading.com/cyberattacks-data-breaches/chinese-actor-deepseek-ai-agent-attack-security-firm πΉ SecurityWeek: Black Hat USA 2026 β Summary of Vendor Anno...
-
Post #4352859
π Security News Digest - 2026-08-03 π 10 updates from 4 sources: πΉ The Hacker News: Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code https://thehackernews.com/2026/08/hugging-face-diffusers-flaws-could-let.html πΉ The Hacker News: N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html π¦ Malwarebytes: A week in security (July 27 &#8211; August 2)...
-
Post #4280544
π Security News Digest - 2026-07-31 π 7 updates from 4 sources: π¦ Malwarebytes: Fake Flash Player installs AtlasRAT https://www.malwarebytes.com/blog/news/2026/07/fake-flash-player-installs-atlasrat πΉ The Hacker News: Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html πΉ The Hacker News: 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026 https://thehackernews.com/...
-
Post #4275317
π Security News Digest - 2026-07-31 π 6 updates from 2 sources: πΉ SecurityWeek: Critical Code Execution Vulnerability Patched in TeamCity https://www.securityweek.com/critical-code-execution-vulnerability-patched-in-teamcity/ πΉ SecurityWeek: CareCloud Data Breach Impacts Over 350,000 https://www.securityweek.com/carecloud-data-breach-impacts-over-350000/ πΉ SecurityWeek: Critical Flaw Led to Azure Cosmos DB Pwnage https://www.securityweek.com/critical-flaw-led-to-azure-cosmos-db-pwna...
-
Post #4262341
πΉ iTnews - Security In Pictures: Security in the age of shadow AI Security Centric roundtable A selection of photos from a recent iTnews roundtable lunch at Bambini Trust restaurant in Sydney. π https://www.itnews.com.au/gallery/in-pictures-security-in-the-age-of-shadow-ai-security-centric-roundtable-627836?utm_source=feed&utm_medium=rss&utm_campaign=iTnews+Security+feed
-
Post #4262340
πΉ SecurityWeek CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems. The post CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs appeared first on SecurityWeek. π https://www.securityweek.com/cisa-urges-water-sector-to-protect-ot-after-coordinated-attacks-on-plcs/
-
Post #4262337
πΉ darkreading Minnesota Water Utility Attacks Expose Sector's Cyber-Risks A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure. π https://www.darkreading.com/ics-ot-security/minnesota-water-utility-attacks-expose-sector-cyber-risks
-
Post #4253412
π Security News Digest - 2026-07-30 π 7 updates from 5 sources: πΉ The Hacker News: DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html πΉ Security News | TechCrunch: Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI https://techcrunch.com/2026/07/30/google-says-it-fixed-more-chrome-bugs-in-june-than-over-the-past-two-years-thanks-to-ai/ πΉ The...
-
Post #4247327
π Security News Digest - 2026-07-30 π 11 updates from 8 sources: π¦ Malwarebytes: Hims &amp; Hers sued over alleged health data privacy failures https://www.malwarebytes.com/blog/privacy/2026/07/hims-hers-sued-over-alleged-health-data-privacy-failures πΉ Threat Intelligence: Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise/ πΉ SecurityWeek: DataBahn Raises...
-
Post #4237131
π Security News Digest - 2026-07-30 π 8 updates from 3 sources: πΉ SecurityWeek: Cisco Secure FMC Zero-Day Exploited in the Wild https://www.securityweek.com/cisco-secure-fmc-zero-day-exploited-in-the-wild/ πΉ The Hacker News: FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks https://thehackernews.com/2026/07/fcc-blocks-new-foreign-produced-robots.html πΉ The Hacker News: Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation...
-
Post #4222376
π¦ Malwarebytes Apple accused of letting fake crypto app steal $1.8 million The case raises fresh questions about how effectively Apple polices apps that impersonate legitimate developers. π https://www.malwarebytes.com/blog/news/2026/07/apple-accused-of-letting-fake-crypto-app-steal-1-8-million
-
Post #4212538
π Security News Digest - 2026-07-29 π 7 updates from 4 sources: πΉ The Record from Recorded Future News: OpenAI says rogue agent behind Hugging Face hack broke into additional services https://therecord.media/openai-says-rogue-agent-behind-hugging-face-hack-broke-into-additional-services πΉ darkreading: Hugging Face Hack Lessons for Cyber Defenders https://www.darkreading.com/cyberattacks-data-breaches/hugging-face-hack-lessons-cyber-defenders πΉ Security News | TechCrunch: US government...
-
Post #4193750
π Security News Digest - 2026-07-29 π 8 updates from 2 sources: πΉ The Hacker News: Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html πΉ The Hacker News: New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html πΉ The Hacker News: OpenAI Agent Used Exposed Credentials Across Four Services...