51 records
Date Area Title Description Source
Cyber
McKesson discloses breach after ShinyHunters claims patient data theft Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...] BleepingComputerEditorial
Cyber
PaperCut releases second emergency patch for exploited flaws PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...] BleepingComputerEditorial
Cyber
Over 8,300 Gitea servers vulnerable to code execution attacks Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. [...] BleepingComputerEditorial
Cyber
Toy-making giant Hasbro disclose data breach affecting employees Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees. [...] BleepingComputerEditorial
Cyber
ServiceNow warns of three max severity security vulnerabilities ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. [...] BleepingComputerEditorial
Cyber Always include
White House bans foreign-made equipment for power generation over cyber backdoor concerns The Trump administration is banning the acquisition of foreign-made components used to manage electricity and power, alleging that “certain foreign actors are increasingly creating and exploiting vulnerabilities” in the technology. The RecordEditorial
Cyber
Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others The arrests come after a wave of cyberattacks earlier this year targeting tech companies that rely on high-profile and widely used open source software. TechCrunch SecurityEditorial
Cyber
CISA confirms hackers targeted over 100 US water systems during July The federal cyber agency's warning comes amid a wave of suspected Iran-backed cyberattacks targeting critical water systems across the United States. TechCrunch SecurityEditorial
Cyber
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42 . Palo Alto Unit 42First party research
Cyber
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42 . Palo Alto Unit 42First party research
Cyber
Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants The private equity giant confirms a breach, weeks after Google researchers said hackers were targeting financial companies. TechCrunch SecurityEditorial
Cyber
AI data giant Alation confirms cyberattack The data search and AI giant confirmed unauthorized access to its systems during an incident on Tuesday, and said it was investigating the breach. TechCrunch SecurityEditorial
Cyber
US says hackers are targeting vulnerable water systems with the help of AI Hackers are targeting internet-connected Siemens controllers used in water facilities around the United States. TechCrunch SecurityEditorial
Cyber
T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network The U.S. phone provider escaped a large-scale breach of its network after identifying Chinese-backed hackers early on. TechCrunch SecurityEditorial
AI
Terabytes of credentials leaked in massive supply-chain attack The data was scraped and exfiltrated from 2,500 users of a compromised AI package. Ars Technica Technology LabEditorial
Cyber Always include
Microsoft Plugs Nearly 400 Security Holes Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today. Krebs on SecurityEditorial
AI
Some GitHub bounty repos are honeypots that farm free work from AI agents Discovered through Hacker News. Open the original report for details. Hacker NewsDiscovery
Cyber
Researcher Tricked Claude, Codex and Hermes into Running Malware Discovered through Hacker News. Open the original report for details. Hacker NewsDiscovery
Cyber
GiveWP WordPress donation plugin flaw lets hackers execute server commands A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...] BleepingComputerEditorial
Cyber
More Americans oppose police license plate cameras than support them: survey The backlash against license plate readers comes amid a wave of police abuses of surveillance cameras. TechCrunch SecurityEditorial
Cyber
AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up? AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation. [...] BleepingComputerEditorial
AI
Authorities arrest 2 alleged members of prolific hacking group TeamPCP The group infected more than 1,000 organizations in a relentless supply-chain attack campaign. Ars Technica Technology LabEditorial
Cyber
Nearly 700 rogue AI agents coordinated in the Hugging Face attack New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board. [...] BleepingComputerEditorial
Cyber
ATF declares ‘major incident’ as ransomware gang claims hack The ATF is the latest federal government agency in recent years to notify Congress of a "major incident" involving its cybersecurity. TechCrunch SecurityEditorial
Cyber
PaperCut warns of NG, MF flaw exploited in zero-day attacks PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. [...] BleepingComputerEditorial
Cyber
Here’s all the times AI has gone rogue and hacked other companies A recap of all the incidents involving LLMs made by Anthropic, Meta, and OpenAI, which went rogue and attacked real companies and individuals on the internet. TechCrunch SecurityEditorial
AI
Claude, Codex, and Hermes installed unowned code inside corporate networks 227 install commands were found in corporate docs pointing at code nobody owns. Ars Technica Technology LabEditorial
Cyber
Australia arrests alleged TeamPCP hackers behind supply-chain attacks Australian authorities have arrested and charged two young men accused of being part of the TeamPCP hacking group linked to a string of far-reaching developer supply chain attacks. [...] BleepingComputerEditorial
AI
How OpenAI let a mob of LLM agents game a test and ransack Hugging Face Without authorization, 1,200 OpenAI agents conspired among themselves to game a test. Ars Technica Technology LabEditorial
Cyber Always include
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses." The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old su… Krebs on SecurityEditorial
AI
AI agents meant to replace Meta workers made “large-scale, disruptive actions” Report shows Meta's challenges replacing people with AI agents. Ars Technica Technology LabEditorial
Cyber
Medical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operations The company won't say if medical devices are affected or if any customer data was exfiltrated. TechCrunch SecurityEditorial
Cyber
US seizes domains of Chinese botnet used to target NASA, Justice Department, and the Senate The Justice Department said that the domain seizures made the botnet and its command and control servers "inoperable," as the domains were hardcoded into the botnet's code and were critical for the botnet's communication and essential operations. TechCrunch SecurityEditorial
Cyber
That fake Grand Theft Auto VI demo is actually just malware Grand Theft Auto fans, eager for news about one of the most anticipated video games of all time, appear especially vulnerable to this new cyberattack. TechCrunch SecurityEditorial
Cyber
Apple rescues Hide My Email feature from the privacy scrap heap Apple says it will no longer ditch using its icloud.com domain for hiding people's email addresses. TechCrunch SecurityEditorial
Cyber
WhatsApp tightens account security with stronger two-step verification and more WhatsApp’s two-step verification previously relied on a six-digit PIN, but now users can choose a longer, alphanumeric password with special characters. TechCrunch SecurityEditorial
Cyber
Alabama launches investigation into OpenAI’s hack of Hugging Face Weeks after OpenAI disclosed that one of its cybersecurity models had gone rogue and hacked AI dataset company Hugging Face, Alabama’s attorney general announced an investigation into the incident. TechCrunch SecurityEditorial
Cyber
Instinct’s powerful AI assistant is raising privacy and security concerns Early testers are raving about what Instinct can do, but some say the AI assistant’s sweeping access, broad terms and ability to act on users’ behalf come with uncomfortable trade-offs. TechCrunch SecurityEditorial
Cyber
Frontier AI labs still won’t say how they’d contain a rogue model A new study finds leading AI labs have few publicly documented plans for containing rogue models, raising questions about preparedness as AI systems increasingly demonstrate unexpected and potentially dangerous behavior. TechCrunch SecurityEditorial
AI
Waymo doubles spending on lobbying in robotaxi battle with Uber Alphabet-owned company is seeking to persuade US regulators to clear a path for fully autonomous taxi services. Ars Technica Technology LabEditorial
Cyber
Senator asks US government watchdog to review how feds use hacking tools Senator Ron Wyden sent a letter to the U.S. federal watchdog requesting a comprehensive review of how the FBI, DEA, ICE's HSI, and the Secret Service use hacking tools and spyware against Americans. TechCrunch SecurityEditorial
Cyber
Someone targeted security researchers using a fake crypto conference as a lure A hacker pretending to work for a leading cryptocurrency news website targeted several cybersecurity professionals using Google Docs as a way to deliver malware. TechCrunch SecurityEditorial
Cyber Always include
Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. Examples of these techniques can be found in our previous blog on UNC6293’s phishing operations. We now track an additional two distinct suspected Russian clusters, UNC7005 and UNC5976, which conduct phishing, abuse OAut… Google Threat IntelligenceFirst party research
AI
Grok exfiltrates user data when malicious instructions are encrypted Cryptographic Context Injection is only the latest way to break an LLM safety guardrail. Ars Technica Technology LabEditorial
Cyber
Researchers say OpenAI revoked their access to limited cyber program The idea behind OpenAI's Trusted Access for Cyber program is to give trusted defenders better models so they can report bugs and vulnerabilities to companies, with the aim of getting flaws patched faster. TechCrunch SecurityEditorial
Cyber
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud. The post Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 appeared first on Microsoft Security Blog . Microsoft SecurityFirst party research
Cyber Always include
Staying Ahead of Adversarial AI Through Agentic Source Code Review Written by: Alex Tselevich, Michael Maturi Introduction Adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must scramble to identify and patch vulnerabilities while attackers deploy machine-speed AI tools against them. By structuring the analysis process, enforcing skeptical validation steps, and injecting domain-specific human expertise directly into the pipeline, we’ve achieved a leap in efficacy. Combining AI models with a deeply structured, human expert-driven orchestration layer to tip the scales… Google Threat IntelligenceFirst party research
AI
Vulnerability giving attackers full control of Macs is under active exploitation Screen-sharing bug lets remote hackers log in without a password. Ars Technica Technology LabEditorial
AI
PBS station fears losing 50TB of data after being ghosted by cloud storage provider "We don't have access to the data on the hardware/servers," Iron Mountain told Ars. Ars Technica Technology LabEditorial
AI
Chrome adopts what may be the best protection yet against account takeovers Device-bound session credentials thwart an increasingly common form of account takeover. Ars Technica Technology LabEditorial
AI
New Pass-ta-key attack reveals all the things we didn't know about passkeys Why passkey apps treat Windows differently than other operating systems. Ars Technica Technology LabEditorial