| Date | Area | Title | Description | Source |
|---|---|---|---|---|
|
Cyber
|
McKesson discloses breach after ShinyHunters claims patient data theft | Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...] | BleepingComputerEditorial | |
|
Cyber
|
PaperCut releases second emergency patch for exploited flaws | PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...] | BleepingComputerEditorial | |
|
Cyber
|
Over 8,300 Gitea servers vulnerable to code execution attacks | Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. [...] | BleepingComputerEditorial | |
|
Cyber
|
Toy-making giant Hasbro disclose data breach affecting employees | Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees. [...] | BleepingComputerEditorial | |
|
Cyber
|
ServiceNow warns of three max severity security vulnerabilities | ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. [...] | BleepingComputerEditorial | |
|
Cyber
Always include
|
White House bans foreign-made equipment for power generation over cyber backdoor concerns | The Trump administration is banning the acquisition of foreign-made components used to manage electricity and power, alleging that “certain foreign actors are increasingly creating and exploiting vulnerabilities” in the technology. | The RecordEditorial | |
|
Cyber
|
Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others | The arrests come after a wave of cyberattacks earlier this year targeting tech companies that rely on high-profile and widely used open source software. | TechCrunch SecurityEditorial | |
|
Cyber
|
CISA confirms hackers targeted over 100 US water systems during July | The federal cyber agency's warning comes amid a wave of suspected Iran-backed cyberattacks targeting critical water systems across the United States. | TechCrunch SecurityEditorial | |
|
Cyber
|
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution | Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42 . | Palo Alto Unit 42First party research | |
|
Cyber
|
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain | Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42 . | Palo Alto Unit 42First party research | |
|
Cyber
|
Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants | The private equity giant confirms a breach, weeks after Google researchers said hackers were targeting financial companies. | TechCrunch SecurityEditorial | |
|
Cyber
|
AI data giant Alation confirms cyberattack | The data search and AI giant confirmed unauthorized access to its systems during an incident on Tuesday, and said it was investigating the breach. | TechCrunch SecurityEditorial | |
|
Cyber
|
US says hackers are targeting vulnerable water systems with the help of AI | Hackers are targeting internet-connected Siemens controllers used in water facilities around the United States. | TechCrunch SecurityEditorial | |
|
Cyber
|
T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network | The U.S. phone provider escaped a large-scale breach of its network after identifying Chinese-backed hackers early on. | TechCrunch SecurityEditorial | |
|
AI
|
Terabytes of credentials leaked in massive supply-chain attack | The data was scraped and exfiltrated from 2,500 users of a compromised AI package. | Ars Technica Technology LabEditorial | |
|
Cyber
Always include
|
Microsoft Plugs Nearly 400 Security Holes | Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today. | Krebs on SecurityEditorial | |
|
Cyber
|
GiveWP WordPress donation plugin flaw lets hackers execute server commands | A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...] | BleepingComputerEditorial | |
|
Cyber
|
More Americans oppose police license plate cameras than support them: survey | The backlash against license plate readers comes amid a wave of police abuses of surveillance cameras. | TechCrunch SecurityEditorial | |
|
Cyber
|
AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up? | AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation. [...] | BleepingComputerEditorial | |
|
AI
|
Authorities arrest 2 alleged members of prolific hacking group TeamPCP | The group infected more than 1,000 organizations in a relentless supply-chain attack campaign. | Ars Technica Technology LabEditorial | |
|
Cyber
|
Nearly 700 rogue AI agents coordinated in the Hugging Face attack | New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board. [...] | BleepingComputerEditorial | |
|
Cyber
|
ATF declares ‘major incident’ as ransomware gang claims hack | The ATF is the latest federal government agency in recent years to notify Congress of a "major incident" involving its cybersecurity. | TechCrunch SecurityEditorial | |
|
Cyber
|
PaperCut warns of NG, MF flaw exploited in zero-day attacks | PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. [...] | BleepingComputerEditorial | |
|
Cyber
|
Here’s all the times AI has gone rogue and hacked other companies | A recap of all the incidents involving LLMs made by Anthropic, Meta, and OpenAI, which went rogue and attacked real companies and individuals on the internet. | TechCrunch SecurityEditorial | |
|
AI
|
Claude, Codex, and Hermes installed unowned code inside corporate networks | 227 install commands were found in corporate docs pointing at code nobody owns. | Ars Technica Technology LabEditorial | |
|
Cyber
|
Australia arrests alleged TeamPCP hackers behind supply-chain attacks | Australian authorities have arrested and charged two young men accused of being part of the TeamPCP hacking group linked to a string of far-reaching developer supply chain attacks. [...] | BleepingComputerEditorial | |
|
AI
|
How OpenAI let a mob of LLM agents game a test and ransack Hugging Face | Without authorization, 1,200 OpenAI agents conspired among themselves to game a test. | Ars Technica Technology LabEditorial | |
|
Cyber
Always include
|
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia | Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses." The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old su… | Krebs on SecurityEditorial | |
|
AI
|
AI agents meant to replace Meta workers made “large-scale, disruptive actions” | Report shows Meta's challenges replacing people with AI agents. | Ars Technica Technology LabEditorial | |
|
Cyber
|
Medical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operations | The company won't say if medical devices are affected or if any customer data was exfiltrated. | TechCrunch SecurityEditorial | |
|
Cyber
|
US seizes domains of Chinese botnet used to target NASA, Justice Department, and the Senate | The Justice Department said that the domain seizures made the botnet and its command and control servers "inoperable," as the domains were hardcoded into the botnet's code and were critical for the botnet's communication and essential operations. | TechCrunch SecurityEditorial | |
|
Cyber
|
That fake Grand Theft Auto VI demo is actually just malware | Grand Theft Auto fans, eager for news about one of the most anticipated video games of all time, appear especially vulnerable to this new cyberattack. | TechCrunch SecurityEditorial | |
|
Cyber
|
Apple rescues Hide My Email feature from the privacy scrap heap | Apple says it will no longer ditch using its icloud.com domain for hiding people's email addresses. | TechCrunch SecurityEditorial | |
|
Cyber
|
WhatsApp tightens account security with stronger two-step verification and more | WhatsApp’s two-step verification previously relied on a six-digit PIN, but now users can choose a longer, alphanumeric password with special characters. | TechCrunch SecurityEditorial | |
|
Cyber
|
Alabama launches investigation into OpenAI’s hack of Hugging Face | Weeks after OpenAI disclosed that one of its cybersecurity models had gone rogue and hacked AI dataset company Hugging Face, Alabama’s attorney general announced an investigation into the incident. | TechCrunch SecurityEditorial | |
|
Cyber
|
Instinct’s powerful AI assistant is raising privacy and security concerns | Early testers are raving about what Instinct can do, but some say the AI assistant’s sweeping access, broad terms and ability to act on users’ behalf come with uncomfortable trade-offs. | TechCrunch SecurityEditorial | |
|
Cyber
|
Frontier AI labs still won’t say how they’d contain a rogue model | A new study finds leading AI labs have few publicly documented plans for containing rogue models, raising questions about preparedness as AI systems increasingly demonstrate unexpected and potentially dangerous behavior. | TechCrunch SecurityEditorial | |
|
AI
|
Waymo doubles spending on lobbying in robotaxi battle with Uber | Alphabet-owned company is seeking to persuade US regulators to clear a path for fully autonomous taxi services. | Ars Technica Technology LabEditorial | |
|
Cyber
|
Senator asks US government watchdog to review how feds use hacking tools | Senator Ron Wyden sent a letter to the U.S. federal watchdog requesting a comprehensive review of how the FBI, DEA, ICE's HSI, and the Secret Service use hacking tools and spyware against Americans. | TechCrunch SecurityEditorial | |
|
Cyber
|
Someone targeted security researchers using a fake crypto conference as a lure | A hacker pretending to work for a leading cryptocurrency news website targeted several cybersecurity professionals using Google Docs as a way to deliver malware. | TechCrunch SecurityEditorial | |
|
Cyber
Always include
|
Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia | Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. Examples of these techniques can be found in our previous blog on UNC6293’s phishing operations. We now track an additional two distinct suspected Russian clusters, UNC7005 and UNC5976, which conduct phishing, abuse OAut… | Google Threat IntelligenceFirst party research | |
|
AI
|
Grok exfiltrates user data when malicious instructions are encrypted | Cryptographic Context Injection is only the latest way to break an LLM safety guardrail. | Ars Technica Technology LabEditorial | |
|
Cyber
|
Researchers say OpenAI revoked their access to limited cyber program | The idea behind OpenAI's Trusted Access for Cyber program is to give trusted defenders better models so they can report bugs and vulnerabilities to companies, with the aim of getting flaws patched faster. | TechCrunch SecurityEditorial | |
|
Cyber
|
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 | Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud. The post Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 appeared first on Microsoft Security Blog . | Microsoft SecurityFirst party research | |
|
Cyber
Always include
|
Staying Ahead of Adversarial AI Through Agentic Source Code Review | Written by: Alex Tselevich, Michael Maturi Introduction Adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must scramble to identify and patch vulnerabilities while attackers deploy machine-speed AI tools against them. By structuring the analysis process, enforcing skeptical validation steps, and injecting domain-specific human expertise directly into the pipeline, we’ve achieved a leap in efficacy. Combining AI models with a deeply structured, human expert-driven orchestration layer to tip the scales… | Google Threat IntelligenceFirst party research | |
|
AI
|
Vulnerability giving attackers full control of Macs is under active exploitation | Screen-sharing bug lets remote hackers log in without a password. | Ars Technica Technology LabEditorial | |
|
AI
|
PBS station fears losing 50TB of data after being ghosted by cloud storage provider | "We don't have access to the data on the hardware/servers," Iron Mountain told Ars. | Ars Technica Technology LabEditorial | |
|
AI
|
Chrome adopts what may be the best protection yet against account takeovers | Device-bound session credentials thwart an increasingly common form of account takeover. | Ars Technica Technology LabEditorial | |
|
AI
|
New Pass-ta-key attack reveals all the things we didn't know about passkeys | Why passkey apps treat Windows differently than other operating systems. | Ars Technica Technology LabEditorial |
No items match these filters.