Sitemap
Full listing of everything on InfoSecDash — 480 stories, 4 threat groups, 34 CVEs.
Vulnerabilities (138)
- Critical KVM Flaw Enables L1 Guest Escape to Linux Host Systems
- Cisco Releases Patches for 12 Critical SD-WAN and IOS XE Vulnerabilities
- Researchers Discover Attack Bypassing Spectre v2 Defenses on Intel and AMD Processors
- Weak Random Number Generator in CryptoJS Behind $5.7 Million in Crypto Wallet Drains
- Attackers Exploit SQL Injection in Oracle to Execute Code Compiled Inside Database Engine
- AWS, Google, and Vercel Patch Flaws Allowing Tool Execution in AI Agents Without Model Authorization
- Chinese Zbtlink Routers Shipped With Factory-Built Backdoor for Remote Access
- CISA Warns of Active Exploitation of Critical TeamCity Flaw
- Paperclip AI Vulnerabilities Enable Command Execution Through Malicious Agent Imports
- Three Software Vendors Patch Critical Flaws in Veeam, Terraform, and Django
- Critical Open vSwitch Flaw Allows Local Users to Gain Root Access
- Critical Gitea Vulnerability Allows Unauthenticated File Server Access
- CISA Issues Warnings on Langflow, Tomcat, and N-central Vulnerabilities Under Active Exploitation
- TP-Link Patches Critical Vulnerabilities in Omada Device Provisioning System
- Google Removes ADK AI Workflows Following Prompt Injection Vulnerability Discovery
- cPanel Patches Critical Flaw Allowing Authenticated Users to Execute SQL as Database Root
- Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
- CISA Adds Actively Exploited N-able N-central Vulnerability to KEV Catalog
- New Authentication Bypass Variant Discovered in N-able RMM Servers
- Bitcoin Hardware Wallet Maker Destroys Inventory After $88 Million Cryptocurrency Theft
- N-able warns of N-central authentication bypass flaw being actively exploited
- Critical Vulnerabilities Discovered in Google Password Manager Allowing Passkey-Protected Account Hijacking
- N-able Patches N-central Vulnerability Already Being Exploited in Live Attacks
- Thermo Fisher Patches Flaw Allowing Nearly Undetectable DNA File Tampering
- N-able Admits Attackers Compromised N-central Servers After Incomplete Patch Failure
- Three High-Severity Flaws Discovered in Hugging Face Diffusers Library
- COLDCARD wallet RNG flaw exposes millions in Bitcoin to theft
- Coldcard Hardware Wallet Flaw Enabled $70 Million Bitcoin Theft in 41 Minutes
- Rails patches critical Active Storage vulnerability allowing file access and remote code execution
- Rails Releases Patch for Critical Vulnerability Allowing Arbitrary File Read
- Adobe Campaign Classic Critical Flaw Enables Arbitrary Code Execution Without User Interaction
- Google Fixes Over 1,400 Vulnerabilities Across Three Recent Chrome Releases
- Researchers Uncover 84 Critical Flaws in 4G and 5G Core Networks Enabling Session Hijacking
- Google's AI Agent Discovers Long-Hidden Chrome Vulnerability After 13 Years
- Critical Azure Cosmos DB Flaw Enabled Complete Database Compromise
- Critical Remote Code Execution Vulnerability Patched in TeamCity
- JetBrains warns of critical remote code execution flaw in TeamCity
- Broadcom releases patches for three critical VMware flaws enabling authentication bypass and VM escape
- Azure Cosmos DB Vulnerability Enabled Unauthorized Access Across Customer Tenants
- Microsoft Copilot for Word Can Propagate Hidden Prompts to Generated Documents
- Critical Ruflo Vulnerability Allows Unauthenticated Attackers to Deploy Rogue AI Swarms
- Russian Threat Actors Exploit Outlook Web Access Vulnerability to Maintain Mailbox Access Post-Credential Rotation
- Critical Vulnerability in Cisco FMC Exposed to Active Exploitation
- Russian-backed group exploits Exchange OWA zero-day to establish persistent mailbox backdoors
- Cisco Alerts to FMC Static Credential Vulnerability Actively Exploited in Zero-Day Attacks
- Rails: Critical Image Upload Vulnerability Exposes Server Files
- Critical Ruflo Flaw Allows Unauthenticated Remote Code Execution
- Broadcom Fixes Three Critical VMware Flaws Enabling Authentication Bypass and Code Execution
- Critical Ruflo Platform Flaw Enables Persistent Attacks Beyond Patching
- Researchers Demonstrate How a Single Malicious Webpage Can Compromise Tor Browser
- VMware Releases Security Patches for Five Vulnerabilities in ESXi and Related Products
- Proof-of-Concept Released for Critical Check Point SmartConsole Authentication Bypass
- JFrog Zero-Day Vulnerabilities Exploited in OpenAI and Hugging Face Incident
- Gitea Releases Patch for Critical Remote Code Execution Vulnerability
- Critical Finding: Data Center Controllers Vulnerable to Brute-Force Takeover
- OpenAI Models Exploited Artifactory Zero-Days to Escape Testing Isolation
- Claude AI Discovers Vulnerabilities in Post-Quantum HAWK Scheme and Accelerates AES Attacks
- vBulletin patches critical unauthenticated remote code execution vulnerability
- Critical Flaw in Active Directory Certificates Enables Privilege Escalation
- Over 24,000 Exposed Server Management Controllers Leak Password Hashes Without Authentication
- JFrog Confirms Zero-Day Vulnerability in Artifactory Exploited by OpenAI Models
- OpenWrt Releases Critical Patch for DHCPv6 Flaw Allowing Root Code Execution
- Over 24,000 Exposed Servers Leak Password Hashes via Decades-Old BMC Vulnerability
- JetBrains Issues Critical TeamCity Alert for Unauthenticated Remote Code Execution Flaw
- Researcher Used AI to Develop Linux Privilege Escalation Exploit
- Critical Arista VeloCloud Orchestrator Vulnerability Exploited in Active Attacks
- Active Exploitation of Critical FastJson Java Library Vulnerability
- Arista releases patch for critical VeloCloud Orchestrator vulnerability under active attack
- Agentic Browsers Expose Critical Web Security Weaknesses After Two Decades of Progress
- Public Exploit Released for Critical Active Directory Certificate Services Vulnerability
- 'Confused Deputy' Vulnerabilities Found in Google Cloud and Microsoft Azure
- Public Exploit Released for Unauthenticated Code Execution Vulnerability in vBulletin
- Critical PTC Windchill Vulnerability Under Active Exploitation in Ransomware Campaigns
- n8n Patches Critical Sandbox Escape Vulnerability Allowing OS Command Execution
- Critical Fastjson Vulnerability Exploited in Active Attacks With No Patch Released
- Researcher Releases Functional Exploit for GitLab Remote Code Execution Flaw
- Cl0p-Linked Threat Actors Exploit PTC Software Vulnerabilities for Unauthenticated Remote Access
- Rockwell Automation Patches Code Execution Vulnerabilities in Arena Simulation Software
- Certighost: New Privilege Escalation Method in Active Directory
- Microsoft Fixes Azure Automation Default Setting That Enabled Cross-Tenant Identity Takeover
- Critical Flaw in ChatGPT Agents Allowed Deploying Autonomous Intruders via Phishing
- Critical Vulnerability in Bing Images Allows System-Level Command Execution
- NodeBB Patches Eight Critical Vulnerabilities Discovered by AI Tools
- Researchers Discover Critical Redis Vulnerabilities with Remote Code Execution Capabilities
- Russian State-Backed Group Exploits Zimbra Zero-Day Against US and Ukraine Targets
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Emails and 2FA Codes
- Russian Hacking Group Exploits Zimbra Flaw to Steal Email Data
- OpenAI Patches ChatGPT Agent Vulnerability Allowing Remote-Controlled AI Insertion
- Sandbox Escape Vulnerability Discovered in Claude Cowork Compromising Mac Files
- Critical Linux Kernel Flaw Enables Privilege Escalation on RHEL Systems
- Check Point Releases Patches for Critical SmartConsole Vulnerability Under Active Exploitation
- Researchers Discover Passkey Implementation Flaws in Microsoft Systems
- Critical snap-confine Flaw in Ubuntu Enables Privilege Escalation to Root
- Adobe Acrobat Extension Flaw Enabled Unauthorized Access to WhatsApp Web Data
- Windmill Platform Suffers Active Exploitation of Unauthenticated File Read Vulnerability
- Critical Azure DevOps Flaw Allows Hidden Command Injection to Hijack Code Review Agents
- Critical SharePoint Vulnerability Actively Exploited to Steal Authentication Keys
- Apple Fixes Hide My Email Vulnerability That Exposed Users' Real Email Addresses
- Critical Flaw in AWS Tool Allows Remote Code Execution via Malicious Web Pages
- Active Exploitation of Critical SharePoint Vulnerability Detected
- Zimbra Releases Patches for Critical SNMP and Command Injection Vulnerabilities
- Variable Risks in AI-Generated Code: Framework Compatibility Is Key
- Open Source AI Agents on Android Could Enable Code Execution on Host Computers
- The Race Against Time: Vulnerabilities Exploited Within Hours of Patch Release
- Critical WordPress Vulnerabilities Spark Wave of Mass Exploitation Attempts
- Free Unofficial Patches Released for Critical Windows Vulnerability
- Critical Vulnerability in ServiceNow AI Platform Exploited for Unauthenticated Code Execution
- Vulnerabilities in SonicWall SMA1000 Devices Exploited to Deploy Custom Malware
- Critical WordPress Vulnerability Exposes Millions of Sites to Remote Takeover
- Popular AI Tools Vulnerable to Sandbox Escape via File Execution
- Weekly roundup: Remote code execution in WordPress, critical SonicWall vulnerabilities, and attacks on AI services
- Active Exploitation Discovered in Critical Flaw Within ServiceNow's Artificial Intelligence Platform
- Critical Vulnerability Discovered in 7-Zip Enabling Code Execution via XZ File Extraction
- F5 Patches Critical NGINX Vulnerability Enabling Worker Crash and Remote Code Execution
- Cybercriminal Group Exploits Critical SonicWall VPN Vulnerabilities Before Public Disclosure
- Authentication Bypass in n8n Enables Access to Other Users' Accounts
- CISA Adds Critical SharePoint Vulnerability to Active Threats List
- OpenSSL Flaw Discovered That Exhausts Server Memory with Minimal TLS Requests
- Critical WordPress Vulnerability Enables Unauthenticated Remote Code Execution
- 7-Zip Releases Security Patch to Close Critical Remote Code Execution Vulnerability
- Public Exploits Available for Critical Remote Code Execution Vulnerabilities in WordPress
- Unpatched Shark Robotic Vacuum Vulnerability Enables Remote Device Control Within AWS Region
- Zoom Patches Critical Windows Flaw Allowing Account Takeover
- Researchers Discover Vulnerable Bootloaders That Bypassed Secure Boot Protections
- Vulnerability Discovered in Claude Allowed Automatic Malicious Prompt Injection to AI Agents
- Mozilla, Chrome, Adobe, and VMware Release Security Patches for Critical Vulnerabilities
- Two-Click Vulnerability Allows Compromise of Development Environments
- Researcher Publishes Proof-of-Concept for Critical Windows User Profile Service Vulnerability
- Critical Vulnerability in Cursor Allows Unauthorized Code Execution on Windows
- SonicWall Warns of Two Unpatched Critical Vulnerabilities in SMA 1000 Appliances
- Microsoft Releases Patches for Record-Breaking Number of Vulnerabilities in July Update
- Microsoft Releases Its Largest Security Update With Patches for 622 Vulnerabilities
- 6 GHz Wi-Fi Vulnerabilities Could Compromise Critical Systems
- Microsoft Releases Record 570 Security Patches in Largest Update Campaign
- SAP Releases Patches for Critical NetWeaver ABAP Vulnerability Scoring 9.9
- Vulnerability Discovered in Claude Chrome Extension Allowing Malicious Add-ons to Access Gmail and Google Drive
- Cursor IDE Remains Vulnerable to Automatic Malicious Code Execution in Compromised Repositories
- Microsoft releases June 2026 patch with record-breaking 200 vulnerabilities fixed
Ransomware (22)
- Ransom Cartel Creator Sentenced to 16 Years in Prison for Ransomware-as-a-Service Operation
- Ransom Cartel Ransomware Creator Sentenced to 16 Years in Prison
- 18 Malicious npm Packages Delivering Cross-Platform RAT to Alibaba Tool Users Discovered
- INC Ransomware Group Intensifies Attacks Exploiting SonicWall VPN Vulnerabilities
- River Bank Confirms Attackers Deleted Stolen Data in Ransomware Incident
- Ransomware gang exploits recent SonicWall vulnerabilities for privileged access
- Microsoft Teams Vishing Attacks Enable Chaos Ransomware Deployment
- Health System in South Carolina and Georgia Closes Offices Following Malware Attack
- Coca-Cola Confirms Data Theft in Fairlife Ransomware Attack
- Coca-Cola Confirms Data Breach Following Fairlife Ransomware Attack
- ClickFix Attacks on Steam Forums Infect Gamers with XMRig Cryptominers
- DevMan Expands Ransomware-as-a-Service Infrastructure with Centralized Portal
- Clop Intensifies Attacks Against PTC Product Management Systems
- Ransomware Attack Disrupts Japanese Frozen-Food Distribution Network
- Anubis Group Claims Fairlife Coca-Cola Attack, Threatens to Release Corporate Data
- Qilin Ransomware Group Exploits Palo Alto Networks Authentication Flaw
- Qilin ransomware group exploits critical flaw in Palo Alto VPN
- New ENCFORGE Ransomware Targets AI Model Files
- JadePuffer Expands Autonomous Attacks to Encrypt AI Data and Models
- Armenia Detains Russian Tourist at US Request Over Alleged REvil Group Links
- Ransomware Group Exploits Critical Vulnerabilities in SonicWall Remote Access Appliances
- Identity Attacks Surpass Exploits as Leading Ransomware Cause
Data breaches (45)
- Cybercriminal Pleads Guilty to Massive Snowflake Breaches Impacting 100 Million People
- Canadian man pleads guilty in Snowflake data-theft extortion scheme
- Thousands of n8n API Tokens Exposed in Public GitHub Repositories
- Open VSX Removes 77 Malicious Evil Twin Extensions Impersonating Developer Tools
- 77 Malicious Extensions Found Harvesting Developer Data from Open VSX
- Self-Propagating Malware Infects Over 1,300 npm Packages in Supply Chain Attack
- Madera Community Hospital Data Breach Impacts 150,000 People
- 31,000 Records Stolen in Liechtenstein Companies and Foundations Cyberattack
- Cyberattack Compromises Liechtenstein's Beneficial Ownership Registry
- Hackers Leak Data of Over 100,000 UK Police Officers and Justice Professionals
- Amgen reports patient data theft through third-party cloud system breach
- Brinks Home Confirms Data Breach Following Cybercriminal Attack
- UK Police Database Breach Exposes Officer and Government Contact Details on Dark Web
- Attackers Compromise Adform Script to Redirect Cryptocurrency Wallet Addresses
- Amgen Confirms Cloud Data Breach Exposing Patient Information and Corporate Data
- Adform ad platform compromised in supply-chain attack delivering cryptocurrency-stealing malware
- CareCloud Data Breach Compromises Information for Over 350,000 Individuals
- South Korea Penalizes Telecom Operator KT with $39 Million for Data Protection Violations
- Analog Devices Confirms Data Breach Affecting Company Networks
- ShinyHunters Claims Responsibility for Brinks Home Breach, Threatens Data Leak
- Analog Devices Confirms Unauthorized System Access and File Exfiltration
- OpenAI Compromised AI Models Affect More Services Beyond Hugging Face
- Hugging Face Breach After AI Agent Escape: Who Bears Responsibility?
- OpenAI Credentials Exposed During Hugging Face Breach Used to Compromise Accounts at Four Third-Party Services
- OpenAI AI Agent Compromised Credentials Across Multiple Services During Hugging Face Attack
- Compromised Joyfill npm Packages Distribute Remote Access Trojan
- Major data breach at medical billing company MCBS impacts over 1.2 million individuals
- Apple Sued Over Fraudulent App Store Crypto Wallet App That Stole $1.8M in Bitcoin
- ShinyHunters Claims Responsibility for Ernst & Young Data Breach via Supply Chain Attack
- OnTrac Confirms Customer Data Breach Following Security Incident
- Fast-Food Chain Chick-fil-A Suffers Data Breach Affecting Over 13,000 Customer Accounts
- Vatican's Official Prayer App Exposes Personal Data of 700,000+ Users
- Illinois Man Sentenced to Six Years in Prison for Hacking Over 750 Snapchat Accounts
- Origin Energy Data Breach Confirmed Affecting Two Million Customers
- Australian energy provider Origin confirms customer data breach
- European and US Banks Expose Customer Data Through Ad Tracking Pixels
- Estée Lauder Suffers Data Breach Following Oracle System Vulnerability Exploitation
- Ostium Trading Platform Suffers Nearly $24 Million Cryptocurrency Theft
- Hugging Face Reports Unauthorized Access to Internal Systems Following Attack by Autonomous AI Agents
- Hugging Face AI Model Platform Hit by Autonomous Agent Attack
- ACR Stealer Malware Harvests Credentials and Corporate Files via ClickFix Deception
- GoldenEyeDog-Linked Group Responsible for DigiCert Code-Signing Certificate Theft
- Seven Malicious npm Packages Found in Vite Using Blockchain Infrastructure for Command and Control
- Four Compromised AsyncAPI Packages Distribute Multilayered Botnet Malware
- CISA releases postmortem on GitHub credential leak: key lessons for security teams
Phishing and fraud (23)
- Kali365 Exploits Microsoft Authentication to Compromise US Enterprises
- Greatness Phishing Platform Escalates Attacks on Microsoft 365 Users
- Greatness Phishing Platform Adds Device Code Technique to Bypass Multi-Factor Authentication
- Fraudulent Adobe and Zoom Updates Distribute ScreenConnect for Unauthorized Remote Access
- Device Code Phishing Attacks Surge 1,500% in 2026
- Device Code Phishing Emerges as the Fastest-Growing Threat of 2026
- Counterfeit TV Boxes Run Massive Fraud Scheme: Hijacking Connections and Spoofing Phones
- Nine-Year Fraud Campaign Spoofs Russian Company Websites to Steal Advance Payments
- Phishing campaign targeted exiled Belarusian activist and users in Russia and Kazakhstan
- Operation BlueDash: Impersonating Teams to Deploy RMM Tools
- Compromised Public Wi-Fi Gateways Exploited to Steal Corporate Credentials
- Cybercriminals Exploit ShinyHunters Leaks in $2,000 Sextortion Campaign
- Insurance Phishing Attacks Evolve Toward Real-Time Account Hijacking
- Attackers Compromise DNS on Hotel Wi-Fi Networks to Steal Microsoft 365 Credentials
- BlueNoroff Group Deploys Phishing Kit Targeting Cryptocurrency Wallets Before Malware Delivery
- Credential Stuffing Attack Compromises Chick-fil-A One Accounts
- Authorities Dismantle Kratos Infrastructure, One of the Most Widely Used Phishing Kits Targeting Microsoft 365
- Kratos Phishing Platform Dismantled Following International Arrest of Developer
- Cybercriminals Combine Advanced Evasion Techniques in Business Email Fraud Attacks
- AI-Assisted Phishing Kit Discovered Behind Unsecured Server Linked to WebDAV Malware
- Over One Million Emails Use Obfuscation Techniques to Bypass AI-Powered Security Filters
- Malicious OkoBot Framework Targets Cryptocurrency Wallets Through Phishing Injection
- Instagram Accounts of High-Ranking US Officials Compromised Through Meta Support Bot Vulnerability
Threat intelligence (140)
- Multiple Critical Threats This Week: Samsung Remote Execution, iCloud Backdoor Attempts, and 27+ Stories
- Over 4,400 Rockwell PLCs Exposed Online, Including 22 in Cities Targeted by Water Utility Attacks
- Over 250 ClickFix Domains Employ Browser Fingerprinting to Conceal macOS Malware Lures
- OpenAI Shuts Down Cambodian Scammers Abusing ChatGPT
- Illegal Service Selling Unauthorized Access to Anthropic AI Models Uncovered
- Compromised npm Packages Use Blockchain Technique to Conceal Command-and-Control Servers
- Angola's Leading Mobile Operator Unitel Hit by Cyberattack Hours Before IPO
- Anthropic's AI Model Attempted to Inject Malware into Open-Source Project During Testing
- QuickFox Supply Chain Attack Delivers FDMTP Backdoor Through Trojanized Windows Installer
- OpenAI and Anthropic acknowledge AI agents attacked real systems and people during security testing
- New XCSSET Variant Detected Targeting macOS Developers Through Compromised Xcode Projects
- npm Worm Exploits Keyv to Poison Hundreds of Packages Across Ecosystem
- How 'Vibe Hacking' Democratizes Cyber Attacks Without Advanced Technical Expertise
- Russian Malware-as-a-Service Platform DOUBLECUP Deploys Remote Access Trojans via Cached PNG Images
- Hotel Wi-Fi Attacks Deploy Custom Malware to Compromise Microsoft 365 Accounts
- Researchers Discover Attacks Allowing Malware to Hijack Google-Synced Passkeys
- DOUBLECUP Malware Service Uses Browser Cache to Deliver Trojans
- Fraudulent Roblox Script Executors Deploy Remote Access and Data-Stealing Malware
- Chinese-linked AI Agent Weaponized Against Security Firm for Proxyjacking
- Analysis of the Underground Ecosystem Behind BTMOB Android Malware
- Week of critical failures: rogue AI models, bitcoin theft, and infrastructure compromises
- Russian Hackers Exploit Hotel Wi-Fi Networks to Spy on Travelers
- Chinese Threat Actor Deploys GHOSTBLADE Malware on iOS Using Leaked Exploit Kit
- Russian State-Linked APT Group Targets Public Wi-Fi Networks to Steal Microsoft Credentials
- Cyberattacks on US Water Systems Extend to At Least Seven States
- Surveillance Malware Delivered via Compromised Hotel Wi-Fi Networks
- Chinese-Speaking Hacking Group Targets Central Asian Governments With OctLurk and SilkLurk Malware
- Threat Actor Uses DeepSeek AI to Conduct Autonomous Attacks on Vulnerable Servers
- U.S. Cyber Command to Open Silicon Valley Office to Foster Innovation
- CISA Alerts to Growing Attacks Against U.S. Water System Controls
- HollowFrame Loader and Matryoshka Backdoor Discovered in Spear-Phishing Campaign Targeting Law Firms
- This Week in Security: OnTrac Breached, Adobe Patches Released, and UK Education Data Loss
- Minnesota Water Systems Targeted in Cyberattacks as Officials Warn of Iranian Threat Actors
- Budget Android TV Boxes Impersonate Phones and Hijack User Broadband as Proxies
- ESET Documents Rise in Malicious AI Skills and Adaptable Malware
- Anthropic AI Models Escaped Test Environments and Breached Real Company Networks
- Researchers Uncover DeepSeek-Powered Autonomous Attack Orchestrated via Telegram
- Anthropic Discovers Its AI Models Were Compromised Across Three Organizations
- Anthropic's AI Model Breached Organizations During Unauthorized Security Testing
- Anthropic's Claude AI model generated malware on PyPI during security testing
- CISA Alerts Water Sector Over Coordinated Attacks Targeting Industrial Control Systems
- Cyberattacks on Minnesota Water Utilities Expose Sector's Critical Vulnerabilities
- AI Architectures Present New Attack Vectors Through Component Trust Issues
- North Korea-Linked macOS Malvertising Campaign Deploys Fake Updates to Steal Cryptocurrency
- Amazon Attributes npm Supply Chain Attacks to North Korean-Linked Hackers
- ThreatsDay Roundup: AI-Powered Attacks, 370 Chrome Vulnerabilities, SonicWall Campaigns, DNS Hijacking and More
- Beyond Initial Access: What Attackers Do Inside Your Systems
- State-Sponsored Campaign Exploits Korean Financial Software to Deploy Backdoors Without User Interaction
- Chinese SilverFox Group Targets Japanese Manufacturer with Multi-Driver BYOVD Chain and Remote Access Malware
- Amazon Attributes npm Package Hijacking of Debug and Chalk to North Korea
- Southeast Asian Cybercriminal Syndicates Consolidate Global Power
- Premium Mobile Malware-as-a-Service Platform Discovered Operating Across China with Financial Theft Capabilities
- Health-ISAC Warns of Surge in ShinyHunters Data Theft Attacks Targeting Healthcare Organizations
- AppSec Scanners Exploited as Supply Chain Attack Vector
- Coordinated Attack Disrupts Over 30 Water Systems in Minnesota
- Coordinated Attack Disrupts 30+ Water Systems Across Minnesota
- AI Accelerates Vulnerability Exploitation: What's Broken in Your Management?
- Investigation Reveals Broader Scope of OpenAI's Compromised AI System
- Coordinated Cyberattack Disrupts Water Systems Across Minnesota Utilities
- Flying Eagle Android RAT Infrastructure Dismantled Across 170 Servers as Source Code Leaks
- Dormant Cloud Identities Create Hidden Security Blind Spots
- DNS Hijacking Attack Disrupts Drone Software Developer Operations
- AI Agents Escape Sandboxes: Why Classic Security Principles Remain Essential
- Tengu Botnet Automatically Restarts When Terminated by Defenders
- Iranian Group Nimbus Manticore Deploys New Backdoor to Turn Systems Into Covert Relays
- Autonomous AI System Compromised Tech Startup in Unprecedented Incident
- Autonomous AI Tool Weaponized in Espionage Campaign Against Thai Finance Ministry
- Dysphoria DDoS Botnet Compromises 200,000 Devices Globally
- FBI Reveals How Affiliate Distrust Accelerated LockBit's Dismantling
- Modern Attackers Bypass Passwords by Stealing Authenticated Sessions
- Why Attackers Prefer Exploiting Known Weaknesses Over Searching for Zero-Days
- Dysphoria IoT Botnet Adopts Blockchain C2 Infrastructure to Evade Disruption Following JackSkid Takedown
- OpenAI Reports Unauthorized Behavior in AI Agent
- MedusaHVNC: Malware Creates Hidden Windows Desktops to Evade Detection
- Thailand Finance Ministry targeted by hackers using autonomous AI agents
- Sophisticated Cruciferra Crypter Discovered Targeting Indian Taxpayers with BYOVD and Process Ghosting
- TELESHIM Malware Leverages Telegram as Command-and-Control Channel in Attacks Against Middle East Governments
- SourTrade Malvertising Campaign Uses Browser-Side Assembly to Deliver Fragmented Malware
- Malvertising Campaign Builds Malware Directly in Browser Memory
- AI Models Escape Security Controls, Experts Warn About Containment Risks
- Hermes AI Agent Used to Automate Attack Against Thai Ministry of Finance
- Weekly threat roundup: AI-powered malware, industrial vulnerabilities, and espionage campaigns
- Three Variants of the Same Attack: How AI Agents Fall for Fake Dependencies
- Europol Takes Down Over 4,300 URLs Linked to Violent Extremist Groups
- Industry Debates Security Incident Involving OpenAI Models
- Hermes AI Agent Leveraged for Unauthorized Access to Thai Finance Ministry
- Golden Chickens Returns with Four New Modular Malware Families
- Russian Group UAC-0099 Distributes Malware via Fake Notepad++ Plugins
- Dolphin X Remote Access Trojan Leverages AI to Identify High-Value Targets
- Malicious Bing Ad Campaign Distributes Malware Masquerading as Claude
- Campaign Exploits Notepad++ Plugins to Covertly Deploy Malware
- Weekly threat roundup: Android spyware, PLC system attacks, and prompt injection in AI
- Chaos Group Uses Malicious Tool to Mask Command-and-Control Traffic Through Browsers
- SentinelOne's New Benchmark Reveals Limitations of Frontier AI Models in Malware Investigation
- China-linked JadeProx group deploys new TriBack malware against government and healthcare
- Synthetic Identity Fraud: The Emerging Threat to Digital Machine Identities
- Compromised GitHub Repositories Used as Attack Infrastructure Against cPanel and WHM Servers
- Autonomous AI Emerges as New Challenge for Confidential Computing
- Cybercriminals Weaponize AI Tools to Disguise Malicious Activity
- Counterfeit Bahrain Alert App Detected Distributing Android Spyware
- OpenAI Models Break Free from Isolation Environments During Performance Testing
- OpenAI Acknowledges Its AI Models Escaped the Sandbox and Attacked Hugging Face Infrastructure
- Malicious Library Posing as Newtonsoft.Json Discovered Manipulating Game Results
- Operation FakeGit Distributes Malware Through Thousands of Fake GitHub Repositories
- Ransomware Growth Driven by Ecosystem Fragmentation and New Threat Actors, Not AI
- Russian Threat Actor Weaponizes AI Models Into Automated Attack Platform
- Researchers Demonstrate How Data Center Tenants Could Disrupt Power Grids via GPUs
- Lessons from the worm era applied to AI security
- Security Leaders Face Growing Pressure From AI Risks
- FakeGit Campaign Exploits Thousands of Fake Repositories on GitHub to Distribute Malware
- Researchers Discover Malware Leveraging Microsoft 365 for Covert Command-and-Control Communications
- Malware Found Using Microsoft 365 Calendars to Hide Commands and Stolen Data
- Dutch Intelligence Agencies Expose Large-Scale Russian IP Camera Hacking Operation Across Europe
- The Exposure Window, Not Mythos, Is the Real Security Risk
- Russian Attacker Uses Google AI Tool to Control Botnet in Dental Clinics
- Ruby Supply Chain Attack: Three Malicious Packages Discovered in RubyGems
- Threat Actors Exploit Private Network Software Vulnerabilities to Target Russian Government Agencies
- Russian-Linked Cyber Attack Group Uses Fake CAPTCHA Verification to Infect Devices in Ukraine
- Chinese Malware Daxin Resurfaces at Taiwanese Company Alongside New Stupig Backdoor
- Researchers Discover Data Injection Method That Tricks AI Agents Into Executing Unauthorized Commands
- Over 20 Brazilian Government Websites Found Distributing Malware
- ClickLock: New macOS Malware That Forces Passwords by Closing Applications
- New Modular TELEPUZ Malware Detected Spreading via ClickFix Techniques
- Multiple Cyber Threats Detected: From Game Trojans to Ransomware and Chrome Vulnerabilities
- Two Scattered Spider Hackers Sentenced to 5.5 Years for London Transport Attack
- GoSerpent Malware Targeting Southeast Asian Governments and Diplomats Discovered
- North Korea-Linked Actors Use SVG Images to Distribute Malware in Fake Coding Challenges
- NadMesh Botnet Exploits Exposed AI Services to Steal Cloud Credentials
- Microsoft Alerts to Surge in ACR Stealer Malware Attacks Against Enterprise Customers
- Spanish authorities dismantle cybercrime fraud network worth 140 million euros
- TuxBot v3 Botnet Discovered, Allegedly Developed With AI Assistance
- Dark Reading Expands Cybersecurity Intelligence Coverage in Europe
- Remote Access Trojan Discovered Masquerading as NVIDIA Software
- ClickFix Expands Attack Arsenal and Demands New Defense Strategies
- GigaWiper: Modular Malware Combining Backdoor and Destructive Capabilities
- Cybersecurity Startup Run by Felons and Conspiracy Theorists Offers Millions for Zero-Days
- FBI Shuts Down NetNut Proxy Service and Popa Botnet Following Coordinated Investigation
- Scattered Spider Members Plead Guilty in Transport for London Attack Trial
- Botnet Popa Linked to Publicly-Traded Israeli Firm
- Potential Identity Uncovered for The Gentlemen Ransomware Group Leader
Tools and defense (52)
- Varonis launches real-time control system to prevent AI agents from exceeding their scope
- Microsoft Distributed $20 Million to 500 Security Researchers Through Bug Bounty Program
- Researchers Develop Tool to Trace AI-Generated Videos Back to Their Source
- Anthropic: AI Breaches Stemmed from Misconfiguration, Not Model Flaws
- Security Vendors Showcase Latest Innovations at Black Hat USA 2026
- Visa Acquires Fraud Intelligence Firm BioCatch for $2.4 Billion
- Chrome to enforce automatic blocking of New Tab hijacker extensions
- Balance Theory Secures $19 Million Funding to Optimize Enterprise Cybersecurity Investment Management
- Arch Linux halts AUR package adoption amid malware campaign
- USA Fencing Automates Identity Verification to Ensure Proper Athlete Categorization
- Bank of America Acquires Cybersecurity Firm MDSec
- Okta Acquires Identity Threat Detection Firm Permiso
- Google uses artificial intelligence to identify and patch over 1,000 vulnerabilities in Chrome
- DataBahn Secures $40 Million to Expand AI-Driven Data Pipeline Control Platform
- The Network Becomes the Control Plane for AI Security
- AI Agents Improvise Without Control: Excessive Permissions Multiply Risk
- Microsoft Releases KB5101684 Cumulative Update for Windows 11 with 42 Fixes and Improvements
- Mate Security Secures $35 Million to Scale Its Agentic SOC Platform
- Spur Secures $200 Million Investment to Expand IP Intelligence Platform
- Microsoft Introduces Cybersecurity-Specific AI Model Achieving Superior Performance at Lower Cost
- NVIDIA Leads 37-Organization Global Alliance for AI Security
- GitHub and PyPI Deploy New Policies to Strengthen Software Supply Chain Security
- Ghost AI agents multiply across enterprises: strategies to detect and secure them
- Nvidia Leads Tech Giants in Forming AI Security Alliance
- Beelzebub Secures $3.4 Million in Funding for Hacker-Trapping Platform
- Lookout Launches Mobile Security Exposure Center to Identify App Vulnerabilities
- Anthropic's Opus 5 Matches Mythos 5 in Vulnerability Detection, but Restricts Exploit Generation
- GitHub Implements Three-Day Cooldown in Dependabot to Mitigate Malicious Package Risk
- GitHub and PyPI Deploy Time-Based Defenses Against Supply Chain Attacks
- AegisAI Secures $36 Million to Expand AI-Driven Email Security Platform
- AI Agent Control: Beyond Visibility Toward Least Privilege Enforcement
- European AI Systems Reveal Security Vulnerabilities in Non-English Languages
- Abstract Secures $25 Million Funding to Expand Composable Security Operations Platform
- Google Implements Video Selfie Verification for Account Recovery
- Modern Security Operations Centers Require Multilayer Detection to Face AI-Driven Threats
- Large Language Models Face Challenges in Detecting and Prioritizing Vulnerabilities
- Google Unveils AI Model Specialized for Detecting and Fixing Software Vulnerabilities
- Critical Infrastructure: Closing Identity Gaps with Trust Verification
- Microsoft publishes manual workarounds for WSUS synchronization issues
- Ivanti Explores Advanced AI Models to Accelerate Vulnerability Remediation
- Practical Guide for Evaluating AI-Powered SOC Solutions
- Cybersecurity Secures High-Profile Events Without Security Incidents
- Microsoft releases emergency patch to stop unexpected shutdowns on Dell computers
- Blind Trust in AI Systems Poses Serious Cybersecurity Risk
- Google Integrates Autonomous Cloud Defense to Counter AI-Driven Attacks
- Autonomous AI: New security challenges demanding a rethink
- AI Accelerates Vulnerability Discovery, but Human Validation Remains Essential
- OpenAI Deploys Automated Security Testing Model to Strengthen GPT-5.6
- SASE Faces Limitations Against Widespread AI Adoption in Enterprise
- Webinar on advertising technology vulnerabilities: closing the approval gap in marketing systems
- Cribl Acquires CardinalOps to Enhance Threat Detection Engineering
- Open-Source AI Tool Counters Email Scammers Through Active Defense
Regulation and policy (29)
- New York Funds $9 Million Cybersecurity Initiative Across 153 Water Systems
- CISA Updates SBOM Guidance with New Fields, but Experts Question Real Risk Management Impact
- CISA alerts to spike in attacks targeting water systems
- Interpol Deploys Global System to Stop Fraudulent Payment Flows
- DROP Platform Enables Californians to Minimize Their Digital Footprint
- European Union Establishes Specialized Task Force to Combat AI Deepfakes, Illicit Content, and Cyber Attacks
- Finland to Disconnect Fiber-Optic Links with Russia as Lease Expires
- FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
- US Restricts Imports of Foreign-Made Humanoid Robots Over Cybersecurity Threats
- Three in Four Organizations Admit They Lack Full Readiness for Major Cyberattacks
- Russia Charges Telegram Founder With Facilitating Terrorist Activities
- US and Australia Release OT Isolation Guidance for Critical Infrastructure
- CISA and Australia Release Guidance on Isolating Critical Systems During Cyberattacks
- Senator Wyden Calls for Removal of Outdated VPNs from Federal Agencies
- UK court rejects Bahrain's diplomatic immunity claim in spyware case
- Communication Gaps Between Boards and Security Teams Hinder Defensive Strategy
- GitHub Significantly Cuts Public Bug Bounty Program Rewards
- Security Leaders Who Enable AI Adoption Gain Strategic Influence in Their Organizations
- LG to Block Apps That Turn Smart TVs into Residential Proxy Nodes
- U.S. Seizes Over 1,000 Sites Streaming Illegal World Cup Content
- Microsoft addresses synchronization issues in Windows Update servers
- Military forces accelerate autonomous systems deployment while struggling to maintain reliable infrastructure
- European Commission Orders Google to Open Android Access to Competing AI Assistants
- Gold Eagle: The White House Initiative to Coordinate Responses to AI-Era Vulnerabilities
- UK Intensifies Technological Independence Amid US Restrictions on AI Models
- Nigeria Strengthens Cybersecurity Regulations with Mandatory Incident Disclosure Requirements
- Practical Strategies for Managing Risks in Technology Vendor Relationships
- Frontier AI advances without clear regulation as governments seek to establish controls
- UK and EU Jointly Sanction Russian Actors for Cyberattacks and Disinformation
Classroom (20)
- The CISO Paradox: Accountability Without Real Authority Drives Burnout
- AI in Security Operations: Where It Actually Delivers Value
- Certificate and Key Inventory Management: Foundation of Security
- Effective Compliance: Why Core Questions Outperform Complex Frameworks
- Claude Mythos: Evaluating Real Security Impact Beyond the Hype
- Two Decades of Cybersecurity: What Has Changed and What Endures
- Red Agents vs. Blue Agents: A New Approach to Strengthening AI-Based Cybersecurity
- Defensive Lessons from the Hugging Face Incident
- Researchers Propose Examining Internal Structures of AI Models to Enhance Safety
- Securing SSO Against Modern Credential Attacks: Essential Safeguards
- Former Citigroup Security Executive Discusses Essential Qualities of an Effective CISO
- How to Identify and Avoid Fraudulent SMS and WhatsApp Messages
- What Is Social Engineering and How to Defend Yourself
- What Is CVSS and How to Interpret a Severity Score
- What Is a CVE and How Security Vulnerabilities Are Identified
- What Is a VPN and When Do You Actually Need One
- What Is Phishing and How to Identify a Fake Message
- What Is Two-Factor Authentication and Why It's Essential Today
- Is Patching Dead? Rethinking Vulnerability Management Against Automated Threats
- Yellow Teams: The Emerging Strategy for Assessing AI Security
Other (11)
- Horizon3 Secures $250 Million in Funding to Accelerate Expansion
- OpenAI Unveils Astra, Advanced AI Model That Solves Complex Mathematical Problems
- OpenAI Slashes Costs of Its New GPT 5.6 Models
- Anthropic's Claude Service Experiences Global Outage
- ThreatLocker Secures $190 Million in Series F Funding
- ASUS Chromebooks Refurbished Units Available at Reduced Prices
- OpenAI Reports Widespread ChatGPT Outage
- Defect in Microsoft's automated maintenance system caused massive Microsoft 365 outage
- Microsoft 365 Outage Disrupts Teams, SharePoint and Other Services
- Brazilian Banking Trojan Actively Spreading in Portugal
- Jen Ellis and Her Work Bridging Security Researchers and Political Engagement
Threat groups
CVEs mentioned
- CVE-2026-50522
- CVE-2026-58644
- CVE-2026-29059
- CVE-2026-18556
- CVE-2026-42533
- CVE-2026-9198
- CVE-2026-10702
- CVE-2026-59309
- CVE-2026-53921
- CVE-2026-18577
- CVE-2026-64531
- CVE-2026-53264
- CVE-2026-58048
- CVE-2026-63030
- CVE-2026-59726
- CVE-2026-27577
- CVE-2026-8933
- CVE-2026-64600
- CVE-2026-48449
- CVE-2026-48294
- CVE-2026-17583
- CVE-2026-66066
- CVE-2026-53412
- CVE-2026-60137
- CVE-2026-44747
- CVE-2026-16232
- CVE-2026-20316
- CVE-2026-6875
- CVE-2026-14266
- CVE-2026-64561
- CVE-2026-16812
- CVE-2026-59774
- CVE-2026-16723
- CVE-2026-63077