THE HUNTER’S LEDGER
The Wire
Threat Intelligence Headlines
Recent threat-intel reporting from public sources, refreshed twice daily. Headlines and links only, every item goes to the original publisher. This is aggregation rather than original research. My original research can be found in the reports section.

Updated 23 August 2026, 19:02 UTC · 499 items from the last 30 days

Generated from my own OpenCTI instance, not scraped

The headlines are other people’s reporting, but the pipeline is mine. Every item here comes out of the OpenCTI threat-intelligence platform I run and maintain myself, the same instance that holds the STIX bundles for every report I publish and feeds the blocklists on my own network. It refreshes twice a day, straight from that platform.

Sunday 23 August 2026
BleepingComputerToxicPanda Android malware uses VPN permissions to block Google Playmobile
Saturday 22 August 2026
BleepingComputerHackers infect Android car head units with proxy botnet malwarehardwareBleepingComputerNamed Pipes Under Attack: Securing Windows Interprocess Communication
Friday 21 August 2026
Palo Alto NetworksConnecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainchaindropinsightsRecorded FutureLawmakers call for investigation into impact of CISA staffing cutsgovernmentleadershipBleepingComputerNew SynkLoader malware pushed in Microsoft Teams phishing campaignSecurityWeekFormer NSA Director Paul Nakasone Launches National Security Advisory FirmuncategorizedRecorded FutureU.S. Bank says breach claims related to fourth-party incidentcybercrimeBleepingComputerHundreds of leaked AWS keys give full control over corporate accountscloudSecurityWeekIn Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bugin other newsvulnerabilitiesRecorded FutureCanada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolencybercrimeprivacySecurityWeekNew Phishing Toolkit Uses Passkeys to Maintain Access After Password Resetsphishingphishing kitRecorded FutureRussian network monitoring firm confirms cyberattack claimed by pro-Ukraine hackerscybercrimeSecurityWeekCritical Isolated-vm Vulnerability Leads to RCE on Hostisolated-vmvulnerabilitiesBleepingComputerCISA orders feds to patch actively exploited TrueConf Server flawsBleepingComputerMicrosoft warns of max severity Entra ID flaw exploited in attacksmicrosoftBleepingComputerHackers abuse FTP server banners to deliver new Windows malwareBleepingComputerSickKids data breach exposes employee and job applicant infoSecurityWeekRust Supply Chain Attack Linked to North Korean HackersarrayrefmalwareAlienVaultHead Mare APT Group exploits vulnerabilities in unpatched TrueConf server to deliver PhantomCore malware to conference participantsbackdoorhead mareSecurityWeekCISA Urges Immediate Patching of Exploited TrueConf Vulnerabilitiescisa kevexploitedAlienVaultSynkLoader: when you throw in everything but the kitchen sinkcredential phishingfake lock screen
Thursday 20 August 2026
AlienVaultSupply Chain Attack on arrayref: Significant Overlap with DPRK Campaignsbackdoorcompile-time executionAlienVaultPopular Rust Crates Compromised in Build-Time Supply Chain Attackbackdoorbuild-time executionRecorded FutureChina’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malwarecybercrimenation-stateCisco TalosIs Cyber missing the Marque?threat source newsletterBleepingComputerHackers poison arrayref Rust crate to push infostealer malwareAlienVaultHow Peer2Profit and Astroproxy Turn Your Bandwidth Into Someone Else's Productastroproxybackconnect infrastructureAlienVaultDistinct Clusters Target Individuals of Interest to Russiaapp password phishingatomicAlienVaultN4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for itai infrastructure targetingcloudflare tunnelsAlienVaultInside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asiaanydeskchrome extensionAlienVaultBRIDGEHEAD: An npm typosquatting campaign that crosses from WSL into Windows to plant a crypto-wallet stealerbrowser-credentialscryptocurrency-stealerSecurityWeekHackers Target Zimbra Servers in Active Exploitation CampaignexploitedvulnerabilitiesBleepingComputerCritical Elementor Pro bug exposes WordPress sites to RCE attacksBleepingComputerHow MSPs can catch phishing attacks email filters missSecurityWeekThreat Actor Hacks 14,000 IP Cameras in Ukraine and RussiacameradahuaSecurityWeekAtlassian, Splunk Patch Dozens of Critical, High-Severity VulnerabilitiesatlassianpatchesBleepingComputerCitrix urges admins to patch new NetScaler flaws as soon as possibleSecurityWeekMLflow Vulnerability Exploited for Cloud Credential TheftexploitedmlflowSecurityWeekCisco Patches Critical Crosswork, Secure Workload VulnerabilitiesciscopatchesAlienVaultChinese-speaking adversary integrates agentic AI into post-compromise operationsagentic aibadiisAlienVaultBlend between Banking Malware & Spywareandroidbanking trojanAlienVaultBack-to-School Cyber Risks Surge as Education Remains the World's Most Attacked Sectorapac attacksback-to-schoolSecurityWeekAI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hackingartificial intelligenceics/otBleepingComputerCISA warns of hackers exploiting critical MLflow vulnerabilityBleepingComputerNew Manic Android malware can exfiltrate data through nearby devicesmobileCisco TalosUAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilitiesthreat spotlightCisco TalosUAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operationsthreat spotlightPalo Alto NetworksIdentity Abuse Through Trusted Communication Channelsauthenticationidentity theftBleepingComputerCritical Zimbra RCE flaw now actively exploited in attacksSecurityWeekExploitation Expected for Critical Authentication Bypass Patched in Citrix NetScalercitrixnetscalerSecurityWeekCritical GitLab Flaw Exploited Shortly After DisclosureexploitedgitlabAlienVault41 deceptive download sites show a real link, then send you somewhere elseaffiliate fraudbait-and-switchAlienVaultSilkParasite: Tracking a China-Nexus APT Across Central Asiabloodalchemycentral asiaSecurityWeekHackers Using AI to Target Siemens PLCs in Critical US Sectorsartificial intelligenceicsCrowdstrikeCrowdStrike Named Strongest Overall Leader in 2026 Frost Radar™: Cloud Workload Protection Platformscloud & application securityAlienVault77 Firefox Extensions Linked to Crypto Wallet and Credential Theftbrowser extension campaigncloudflare workers
Wednesday 19 August 2026
BleepingComputerRogue ransomware affiliate poses as data recovery firm to steal paymentsBleepingComputerSakura Internet hack exposes data of up to 1.36 million accountsAlienVaultGrandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaignanti-analysisbanking trojanAlienVaultBackdoor delivered through software updatesadblockerbackdoorBleepingComputerHealthtech firm CareCloud data breach impacts 3.7 million patientshealthcareRecorded FutureElectronic health record company CareCloud says 3.7 million people affected by breachcybercrimeBleepingComputerHackers compromise 14,500 Dahua web cameras in 35-day campaignhardwareRecorded FutureNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologycybercrimegovernmentBleepingComputerUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureAlienVaultPost-DEF CON Phishing Uses Malicious Google Doc to Deliver Malwareamosatomic macos stealerBleepingComputerUS charges Iranian hackers over $3.4 billion intellectual property theftlegalAlienVaultScammers are using fake crypto AML checkers to drain your walletcrypto scamcryptocurrencyAlienVaultBalonx Sistema: The Face Behind the PhaaS Affecting Mexican Bankingai vishingandroid ratBleepingComputerPassword spraying attacks surge 155x as hackers exploit MFA gapsAlienVaulthttps://malbearlabs.com/shadow-hvnc-and-shadow-loader-the-kit-that-protects-its-license-better-than-its-customers-dd99520b6af3Recorded FutureUS charges Iranians for sprawling hacking campaign on government agencies, universitiescybercrimenation-stateSecurityWeekUS Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of ThemchargedcyberwarfareAlienVaultFrom ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panelclickfixcryptocurrency theftSecurityWeekCl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaigncl0pdata breachesSecurityWeekCISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple VulnerabilitiesapplecisaBleepingComputerCritical RCE flaw in Windows IKE Extension now actively exploitedmicrosoftCisco TalosDescribing attacks with crime script analysison the radarSecurityWeek943 Patches Rolled Out With Oracle’s August 2026 Security Updateoracleoracle cspuSecurityWeekChrome, Firefox Updates Patch Dozens of VulnerabilitieschromefirefoxBleepingComputerCISA: Medusa ransomware hit over 500 critical infrastructure orgsAlienVaultBeware of Phishing Emails Disguised as Quote Confirmation Requests (PhantomStealer)byovdclipperSecurityWeekCareCloud Data Breach Impact Grows to 3.7 Million Individualscareclouddata breachesAlienVaultClop Returns with Custom Implant in Mass-Extortion Campaigncredential theftcve-2021-27101CrowdstrikeBenchmaxxing: When the Benchmark Becomes the Targetsecuring ai
Tuesday 18 August 2026
AlienVaultCopyCop Targets AI Investment in Armeniaai infrastructurearmeniaAlienVaultMirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US2fa bypassadversary-in-the-middleAlienVaultMacSync Stealer: C2 Infrastructure Rotationc2 infrastructureclickfixPalo Alto NetworksThreat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)credential-based attackshigh profile threatsRecorded FutureMore than 200 victims of Medusa ransomware identified over the last year, CISA sayscybercrimegovernmentBleepingComputerClop created custom web shell for Windchill data theft attacksRecorded FutureBerlin cuts two state ministries off government network after security breachcybercrimegovernmentAlienVaultSigned Overwolf Binary Sideloads ValleyRAT Malware in Indiaastral-pedll sideloadingAlienVaultFraudulent Employment Operationsai-generated personaschatgpt abuseAlienVaultOctagon: A New Android Bot Targeting Crypto Wallets and Banking Appsaccessibility abuseandroidRecorded FutureHackers target Ukrainian agency managing assets seized from sanctioned RussianscybercrimegovernmentBleepingComputerYour Controls Block Known Attacks. What About the Behavior?SecurityWeekAI-Driven Vulnerability Surge Breaks the Traditional Patching Modelartificial intelligencepatchSecurityWeek300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin FlawpluginvulnerabilitiesBleepingComputerCISA: Windows Task Host flaw now exploited by ransomware gangsmicrosoftAlienVaultBeware of Phishing Emails Disguised as Transaction Receiptsliving-off-the-landpdf attachmentSecurityWeekHeights Finance Data Breach Impacts at Least 1.2 Million Individualsdata breachesheights financialSecurityWeekGitLab Patches Critical Code Injection VulnerabilitygitlabpatchBleepingComputerMicrosoft starts removing WMIC tool used by cybercriminalsmicrosoftAlienVaultOperation ASTERIX: Anatomy of a Crypto Fraud Pipelineaccount-enumerationai-assisted-developmentSecurityWeekDozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updatesapplemobile & wireless
Monday 17 August 2026
Recorded FutureUkrainian software developer faces 12 years in Swiss ransomware trialcybercrimeRecorded FutureNearly 750k had financial info, SSNs leaked in South Carolina loan company breachcybercrimeBleepingComputerHacker claims 3.6 million Azure account records stolen from major companiesBleepingComputerPokémon Center data breach exposes customer info, cancels some ordersRecorded FutureSafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impactedcybercrimeprivacyRecorded FutureIrregular faces criticism over ‘spin’ in AI hacking postmortemindustryAlienVaultProjextor: Abusing Electron in Trojanized Productivity Applicationsdesktop captureelectron frameworkAlienVaultC2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2backdoorc2looperAlienVaultOperation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoorchina-nexuscloudflare workersSecurityWeek680,000 Impacted by French Tax Authority Data Breachdata breachesdgfipSecurityWeekIrregular Details How a Naming Error Let AI Models Attack a Real Companyartificial intelligenceai testingBleepingComputerPhilips and GE investigating Clop ransomware data theft claimsSecurityWeekConflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malwareartificial intelligenceanthropicBleepingComputerFrench tax authority data breach affects 678,000 individualsSecurityWeek40,000 Impacted by SafePal Data Breachcryptocurrencydata breachesBleepingComputerMicrosoft working on Defender patch for ShieldBreak zero-daymicrosoftSecurityWeekRecent macOS Screen Sharing Vulnerability Exploited in AttacksexploitedmacosSecurityWeekCritical SAP Commerce Cloud Vulnerability Exploited 3 Days After DisclosureexploitedsapSecurityWeekFortune 500 Companies Hit in Azure Data Theft Campaignazurecloud securityCrowdstrikeTeaching AI to Reason Through Detection Triagesecuring ai
Sunday 16 August 2026
BleepingComputerSafePal data breach impacts 39,798 customers, stolen info for saleBleepingComputerLarge-scale DDoS attacks disrupted Threema secure messaging serviceBleepingComputerNew AmnesiaStealer macOS malware hijacks browser sessions via remote control
Saturday 15 August 2026
BleepingComputerNew Evooo1Bot Linux botnet turns routers into traffic relay nodes
Friday 14 August 2026
Recorded FutureInvestigation of banking hack leads to arrests in Germany, BrazilcybercrimegovernmentBleepingComputerHackers arrested over €30M bank fraud exploiting service provider flawlegalAlienVaultNew Mirai-Based Linux Botnet 'Evooo1Bot' Turns Victims Into Proxiescve-2007-3010cve-2016-6277BleepingComputerHackers exploit macOS Screen Sharing flaw to deploy Monero minerappleBleepingComputerThe Modern Attack Chain: Rethinking Google Workspace Security in the Age of AIBleepingComputerMax severity SAP Commerce Cloud flaw now targeted in attacksRecorded FutureFrance investigates tax authority breach after hacker claims 600,000 victimscybercrimegovernmentSecurityWeekIn Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilitiesin other newsvulnerabilitiesBleepingComputerShell investigates 'potential incident' after Clop data theft claimsSecurityWeekTrivy, Not LiteLLM Behind the 2,500 Org Compromiselitellmsupply chainBleepingComputerRingCentral data breach exposed info of 1.6 million accountsAlienVaultCoolClient backdoor goes deeper: Windows kernel rootkit addedcoolclienthoneymyteSecurityWeek1.6 Million Likely Impacted by RingCentral Data Breachdata breachesdata leakSecurityWeekOver 1,000 Charities Hit by Beacon CRM Data BreachbeaconcharitySecurityWeek14,000 Trezor Customers Impacted by Data Breach at ShipMonkdata breachesmetabaseAlienVaultDropcatch Scavengers: Expired Malicious Domains Become Cash Cowsaffiliate frauddropcatchSecurityWeekHackers Exploiting Unpatched GeoServer Zero-DayexploitedgeoserverSecurityWeekAmnesiaStealer macOS Malware Steals Data, Controls Browser Sessionsamnesiastealerinformation stealerBleepingComputerApple sends new ‘Threat Notification’ alerts over mercenary spyware attacksapple
Thursday 13 August 2026
BleepingComputerUkraine shuts down 94 fraudulent call centers, seize millions in cashBleepingComputerAkira hackers disable EDR with Safe Mode, steal data but fail to encryptAlienVaultMulti-Functional Linux Botnet "Evooo1Bot"ddos engineedge device exploitationBleepingComputerHackers breach govt webmail while running parallel crypto fraudCisco TalosCuriouser and Curiouserthreat source newsletterBleepingComputerMicrosoft patches LegacyHive Windows zero-day vulnerabilitymicrosoftBleepingComputerCritical VMware vCenter RCE flaw exploited for reverse SSH accessAlienVaultPATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructuregatesentinelgoogle sheets c2AlienVaultIllegal Streaming Fronts a $7M Dropcatch Domain OperationasyncratdcratRecorded FutureNew Mirai variant adds stealth capabilities to notorious botnet codecybercrimeBleepingComputerTrezor discloses data breach affecting nearly 14,000 customersBleepingComputerWhite House taps security firms for offensive hack-back operationsAlienVaultRecent Attack Activity Analysis Using North Korea-Related Lureschacha20 encryptiondarkhotelSecurityWeekWordPress 7.0.4 Patches Remote Code Execution VulnerabilityrcevulnerabilitiesRecorded FutureGermany moves to give spy agencies hacking and sabotage powerscybercrimegovernmentAlienVaultJewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by SideantinoaptAlienVaultAPT Group Runs Espionage and Crypto Fraud Operations Side by SideantinoaptAlienVaultNew Armored Likho tools target Telegram and eavesdroppingaquilarataudio surveillanceAlienVaultChina-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud businessantinoantino backdoorSecurityWeekFortinet Patches Authentication Flaws in FortiWeb and FortiManagerfortinetpatchesCisco TalosDissecting the JWR phishing frameworkcisco talos antiviruscisco talos dns securityAlienVaultInside a Ukrainian IP Camera Toolkitcamviewcve-2017-7921AlienVaultState Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploitaerospace targetingcve-2025-49113SecurityWeekCritical VMware vCenter Vulnerability in Attackers’ CrosshairsexploitedvmwareSecurityWeekNightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’chaotic eclipseexploit
Wednesday 12 August 2026
BleepingComputer"City-Forum" data-theft attacks target Salesforce, ServiceNow portalsBleepingComputerAndroid malware combo takes out loans and relays victims' credit cardsmobileAlienVaultInside Multi-Stage Phishing Redirection Chainsbrand impersonationcloudflare workersBleepingComputerHackers exploit critical Adobe Commerce flaw to hijack customer accountsRecorded FutureFBI: Hackers using social engineering to breach accounts and steal explicit contentcybercrimegovernmentAlienVaultCl0p Ransomware: Attack Pattern in Threat Intelligencearchitectural vulnerabilitycve-2023-34362AlienVaultHits Safe Mode: Ransomware Rebooting Around EDRakiraanydeskBleepingComputerPlug and Pwn attack uses fake USB devices for Windows SYSTEM accessmicrosoftBleepingComputerLazarus hackers exploited Windows zero-day to target defense firmsSecurityWeekSharePoint Vulnerability Exploited Shortly After PoC ReleaseexploitedpocBleepingComputerFBI: Hackers target online accounts to steal nude photosAlienVaultStriking gold: Inside the GoldDigger Android malwareaccessibility abuseandroid trojanSecurityWeekWhatsApp Unveils New Scam Alert Featurefraud & identity theftscamSecurityWeekStealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom ToolsetmalwaresalesforceRecorded FutureMicrosoft’s massive Patch Tuesday releases continue as AI reshapes bug discoverycybercrimeBleepingComputerHackers leverage new Microsoft SharePoint exploit in attacksmicrosoftAlienVaultGone with the WindRelay: A New Malware Combo Behind a Growing Fraud Schemeandroid banking trojancontactless payment fraudRecorded FutureCISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaigncybercrimegovernmentBleepingComputerSignal adds new security feature to thwart man-in-the-middle attacksSecurityWeekChipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combinedamdchipmaker patch tuesdayBleepingComputerNew Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privilegesmicrosoftSecurityWeekOver 2,500 Organizations Impacted by LiteLLM Supply Chain Attacklitellmsupply chain attackSecurityWeekFresh Windows Zero-Day Exploited in North Korean CyberattacksaptexploitedSecurityWeekIvanti EPM Update Patches Remotely Exploitable FlawsivantipatchSecurityWeekICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contacticsics patch tuesdaySecurityWeekSonicWall Patches Critical Vulnerabilities in Discontinued GMS PlatformgmssonicwallAlienVault737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirectionbrand impersonationbrowser hijackingSecurityWeekCisco Patches Firewall Zero-Day Exploited for DoS AttacksciscoexploitedAlienVaultTracking Shai-Hulud: Inside the ChainDrop NPM Wormchaindropethereum c2AlienVaultCaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentialsapt29captive portal compromise
Tuesday 11 August 2026
Cisco TalosMicrosoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiespatch tuesdayBleepingComputerDeadLock ransomware uses blockchain to resist infrastructure takedownBleepingComputerSandworm hackers target IT pros with trojanized WireGuard VPN clientAlienVaultFake CCleaner installs GhostDesk Chrome spywarechrome extensionghostdeskAlienVaultShattering the Dream - When a Job Offer Becomes a Zero-Day Attackcve-2026-68820dprk-linkedBleepingComputerCisco warns of ASA and FTD VPN flaw exploited to crash devicesRecorded FutureRansomware group hijacks hospital system’s Facebook page amid ongoing cyberattack falloutcybercrimeSecurityWeekAugust 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-DayexploitedmicrosoftBleepingComputerDelta probes Wi-Fi deauth attack on flight carrying DEF CON attendeesBleepingComputerMicrosoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysmicrosoftSecurityWeekAdobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flawsadobepatch tuesdayAlienVaultCNCMachineRMS: The Undocumented RAT At the End of a BabaDeda ChainbabadedaclickfixBleepingComputerWesco confirms security incident after ExfilSquad claims data theftSecurityWeekZoom Patches Zero-Click Code Execution VulnerabilityvulnerabilitieszoomAlienVaultHow the ErrTraffic Malware Campaign Uses ClickFix and EtherHidingbabadedaloaderblockchainAlienVaultPhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf serverarcbridgebackdoor deploymentAlienVaultAn Evolution of the Botnetaisuruandroid tv boxesAlienVaultSelf-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attackchaindropci/cd compromiseSecurityWeekSAP Patches Critical Code Injection, Memory Corruption Vulnerabilitiespatch tuesdaypatchesBleepingComputerDDoS attacks over 1 Tbps surged fivefold in the second quarterBleepingComputerCISA: Microsoft SharePoint flaw now exploited in ransomware attacksmicrosoftAlienVaultProject CAV3RN uses Google Apps Script for stealthy C2 in Israelc2 relaycommunicationuxtheme.dllAlienVaultFake popular sites offer a free app, instead take over PCsbrand impersonationcryptocurrency lureBleepingComputerCisco warns of high-severity ClamAV flaws with public exploitsPalo Alto NetworksKimwolf v7: An Evolution of the Kimwolf Botnetandroid apkethereumSecurityWeekHacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemptionhackerhacker conversationsBleepingComputerUS and South Korea warn of Gunra ransomware targeting govt agenciesCrowdstrikeAugust 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEsexposure managementAlienVaultThe Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communicationsaeternumblockchain c2Elastic13 million tool calls: auditing every AI coding agent action with Elastic Agentsecurity-labs
Monday 10 August 2026
BleepingComputerHackers breached a small Polish energy plant via private APN last yearPalo Alto NetworksThe Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communicationsaeternuminfection chainBleepingComputerBdThemes plugins supply-chain hack creates rogue WordPress adminsRecorded FutureFBI, South Korea warn of Gunra ransomware gang targeting critical infrastructurecybercrimegovernmentAlienVaultAbyssos: Technical Analysis of a New Modular RATabyssoscustom tcp protocolBleepingComputerNew StormEncryptor ransomware used by former Medusa affiliateRecorded FutureRussian military hackers pose as recruiters to target Ukrainian IT workerscybercrimegovernmentMicrosoftDeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructurecredential theftextortionBleepingComputerCISA: SonicWall SMA1000 flaws now exploited by ransomware gangsAlienVaultInvestigating a Multi-Stage PowerShell Loaderbase64hidden executionSecurityWeekCisco Warns of High-Severity ClamAV Vulnerabilities With Public PoCciscoclamavBleepingComputerWhen Credentials Are No Longer Enough: Device Trust in the AI EraAlienVaultIntegrating AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLMai integrationaptAlienVaultPowercat malware campaign: Fake game cheats deliver infostealercryptocurrency theftdiscord hijackingRecorded FutureChina-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warnschinacybercrimeSecurityWeek‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Badartificial intelligenceghostjackingRecorded FutureNew Zealand sanctions Russian hackers, propaganda groups over Ukraine warcybercrimegovernmentBleepingComputerValve notifies Steam hardware customers of a data breachSecurityWeekMetabase Patches Vulnerability Exploited as Zero-DayexploitedmetabaseSecurityWeekNovel Private APN Pivot Let Hackers Sabotage Second Polish Energy FacilityenergyicsBleepingComputerCritical Progress LoadMaster flaw now actively exploited in attacksSecurityWeekCISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerabilitycisa kevexploitedSecurityWeekCorporate Data Stolen in Levi Strauss Cyberattackdata breacheslevi strauss
Saturday 8 August 2026
BleepingComputerHackers breach TrueConf to trojanize client installers with backdoorsSecurityWeekCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Dataartificial intelligenceatlassian
Friday 7 August 2026
ElasticLiving off the coding agent: Two tales of tunnels and LaunchAgentssecurity-labsPalo Alto NetworksInside the Modern SOC: The Identity Front Doorartificial intelligenceidentityAlienVaultRussian AI Slopsquatting Publishes 700+ Malicious NPM Packagesdns-tunnelinginfostealerBleepingComputerMetabase SQLi zero-day exploited in customer data-theft attackssoftwareBleepingComputerUnlimited Technology Systems breach impacts 3.8 million peoplehealthcareBleepingComputerLevi Strauss & Co. says hackers stole corporate data in cyberattackRecorded FutureIrregular, firm behind AI hacking incidents, won't say if there were moreSecurityWeekIn Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Streetartificial intelligencein other newsBleepingComputerReal emails, hijacked payments: Two H1 2026 attack chainsRecorded FutureLevi Strauss says hackers breached employee computers, accessed corporate datacybercrimeindustryRecorded FutureFrench rugby club Stade Français restores systems after cyberattack, probes data leakcybercrimeSecurityWeekVishing Extortion Group UNC6671 Rebrands After Making MillionscybercrimemalwareAlienVaultInside a Self-Propagating npm Wormblockchain c2chaindropAlienVaultAnalysis of a Modular Cyber Espionage Frameworkbrowser password decryptorcentral asiaSecurityWeek3.8 Million Impacted by Unlimited Technology Systems Data Breachdata breacheshealthcareAlienVaultFake Zoom Installer Delivers Overlord RAT on macOS.net downloadercross-platform malwareSecurityWeekCritical Vulnerabilities Patched With Chrome 151 UpdatechromepatchCrowdstrikeCrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESXnext-gen siem & log managementAlienVaultPayroll Pirates: Strange New Tides in Business Email Compromiseaitm phishingbec campaignElasticThe security signal log tailing can't see: tracking npm cooldown removals with Elastic Agentsecurity-labs
Thursday 6 August 2026
BleepingComputerClickFix attack pushes macOS infostealer for crypto theft attacksPalo Alto NetworksChainDrop: Inside a Self-Propagating npm WormblockchainchaindropAlienVaultUNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environmentsadversary-in-the-middleblackfileAlienVaultMulti-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environmentsadversary-in-the-middleblackfileBleepingComputerSwiss government SharePoint breach compromised 200 accountsBleepingComputerNew TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashesCisco TalosWhy metaphor may dictate your security strategythreat source newsletterAlienVaultMac Malware Drains Crypto Wallets Via Fake CAPTCHA Scamaeza groupclickfixAlienVaultDissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malwarecredential harvestingcryptocurrency wallet theftBleepingComputerMeta AI model hacked a company during misconfigured cyber testSecurityWeekSnowflake Hacker Pleads Guilty in US CourtcybercrimehackerRecorded FutureBelarusian cybercriminal behind Ransom Cartel gets 16-year prison sentencecybercrimemalwareAlienVaultChainDrop npm Attack Compromises Hundreds of Packageschaindropcredential theftSecurityWeekZero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Postsartificial intelligencechatgpt atlasAlienVaultAnalysis of the Connection Between Xctdoor and Past CRAT Attack CasesbackdoorcratPalo Alto NetworksToken Jacking: Cybercriminals Could Be Stealing Your AI Resourcesai apiai gatewaySecurityWeekMeta AI Hacked External Systems During Cybersecurity Testingartificial intelligencemetaAlienVaultHere We Go Again - JavaScript Payload Analysisci compromisecredential theftAlienVaultMajor Shai Hulud campaign strikes npm again, affecting keyv and 400+ packagesaws-secretscacheableAlienVaultAuthentication Bypass Vulnerability in N-central Exploited In-The-Wildauthentication bypasscloudflaredSecurityWeekCisco Patches Critical SD-WAN, IOS XE, FMC VulnerabilitiesciscopocSecurityWeekHackers Start Exploiting Recent JetBrains TeamCity VulnerabilityjetbrainsteamcityCrowdstrikeExpanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discoverysecuring ai
Wednesday 5 August 2026
AlienVaultShai-Hulud strikes again: CHAINDROP worm hits 400+ npm packageschaindropchaindrop wormBleepingComputerRansom Cartel ransomware creator sentenced to 16 years in prisonBleepingComputerCanadian pleads guilty to Snowflake cloud data-theft attacksRecorded FutureCanadian man pleads guilty to Snowflake hacks that led to 165 breachescybercrimepeopleBleepingComputerHackers run khunt post-exploitation toolkit from Oracle databaseSecurityWeekHow a $50,000 Exploit Chain Turned Bixby Against Samsung Phonesbixbyblack hatAlienVaultHow fake signups drive AI fraudai fraudbot networksBleepingComputerCOLDCARD security audit phishing attack installs remote access toolBleepingComputerCISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flawsMicrosoftFrom open lures to cloaked gates: How a macOS ClickFix campaign learned to hideclickfixBleepingComputerGoogle Blogger locks hundreds of blogs in malware false positivegoogleAlienVaultFake CAPTCHA, Real Business: Traffic Distribution for Hireai assistant exposurefakecaptchaAlienVaultENDLESSDOORS Is Phoning Home. Pick Up.cve-2026-66747endlessdoorsBleepingComputerHow AI-powered phishing killed blocklists for goodAlienVaultSecuritySnack - Account Farmers and Sellersaccount farmingaccount traffickingRecorded FutureAnthropic AI agent faked identities, phished real developers in UK government hacking testgovernmentmalwareSecurityWeekNew Attack Methods Enable Malware to Hijack Passkey-Protected Accountsgoogleidentity & accessSecurityWeek311,000 Impacted by Brown Health Medical Group-MA Data Breachbrown healthdata breachesSecurityWeekCISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilitiesapache tomcatcisa kevSecurityWeekOver 400 NPM Packages Infected in ChainDrop Supply Chain AttackchaindropmalwareAlienVaultQuickFox Supply Chain Attack Used to Deploy FDMTP Implantdll sideloadingelectron applicationAlienVaultChainDrop: The Mini Shai Hulud npm worm's latest wave hits keyv and cacheablechaindropcredential harvestingAlienVaultThe Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2blockchain c2chiselAlienVaultSupply Chain Compromise Affecting keyv and cacheable npm Packagesci/cd compromisecloud credentials
Tuesday 4 August 2026
MicrosoftChainDrop supply chain compromise: Anatomy of a self-propagating wormnpmsupply chain attackBleepingComputerTP-Link patches Omada ZTP flaws allowing hackers to breach networksBleepingComputerPhishing service spoofs RingCentral to steal Microsoft 365 accountsRecorded FutureOpenAI: Cambodian scam centers used ChatGPT to lure Indian nationals, conduct investment fraudcybercrimeBleepingComputerNew XCSSET variant targets macOS devs via compromised Xcode projectsAlienVaultSecurity Update – August 2, 2026administrative accesscloudflare tunnelAlienVaultFake AI Tools Deliver Infostealerai developersblockchain c2AlienVaultScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Securitycloudflare tunnelscode signing abuseAlienVaultRMM Abuse Analysiscloudflare tunnelscode signing abuseAlienVaultnpm Packages Hijacked in Supply Chain Attackcacheablecredential theftAlienVaultPhishing Email Delivers ScreenConnect Malwarebank of america impersonationbase64 obfuscationRecorded FuturePolish convenience store chain Żabka hacked through third-party accountcybercrimeindustryBleepingComputerMassive ChainDrop npm supply-chain attack infects hundreds of packagesSecurityWeekWeaponized Email AI Assistants Could Help Attackers Hijack Accountscybercrimeemail securityPalo Alto NetworksThe Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Softwareartificial intelligencefrontier aiPalo Alto NetworksAlmost Half of Malware Samples Communicate Direct to IPcommand and controld2ipRecorded FutureSwiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspectedgovernmentSecurityWeekTP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeovernetwork securityomadaSecurityWeekGemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tamperingagent-to-agentartificial intelligenceCisco Talos“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AIartificial intelligencelanding page top storySecurityWeekDecades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacksbmcdata centerAlienVaultNightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and AfricaarcbridgebridgeheadAlienVaultClickFix-Themed Campaign Deploys Starland RAT and WLDR Frameworkcastlestealerclickfix campaignSecurityWeek150,000 Impacted by Madera Community Hospital Data Breachdata breacheshealthcareAlienVaultWhatsApp account takeover scam asks you to "vote for my friend"account takeoverlinked devices abuseCrowdstrikeSecure Agent Harness Execution: Preventing Escapesecuring aiBleepingComputerHotel Wi-Fi attacks use custom malware to breach Microsoft 365 accountsElasticAgents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a humansecurity-labs
Monday 3 August 2026
BleepingComputerNew Pass-ta-key attacks let malware hijack Google-synced passkeysAlienVaultTargeted Attack on Government Entities in the Middle East | Part 2backdoorbindcloakRecorded FutureBitcoin hardware wallet maker destroys some inventory after more than $88 million stolencybercrimeBleepingComputerNew DOUBLECUP ClickFix service hides malware in browser cache imagesBleepingComputerFake Roblox Xeno script launcher pushes infostealer, RAT malwaregamingRecorded FutureHackers steal 31,000 records identifying people behind Liechtenstein companies, foundationscybercrimegovernmentBleepingComputerN-able warns of N-central auth bypass flaw exploited in attacksAlienVaultAnalysis of a Phishing Email Attack Casecredential theftheptaxCisco Talos[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidentscisco talos incident responseBleepingComputerExfilSquad hackers leak info of over 100,000 UK police officers, staffBleepingComputerInside the Underground Business of BTMOB RATSecurityWeekRiver Bank Says Hackers Deleted Data Stolen in Ransomware Attackbankdata breachesBitDefenderFake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forumsanti-malware researchRecorded FutureBiotech giant Amgen says patient data stolen from third-party cloud systemscybercrimeSecurityWeekN‑able Patches Vulnerability Exploited to Hack N-central Serversexploitedn-ableRecorded FutureRussian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft saysmalwarenation-stateSecurityWeekBrinks Home Discloses Data Breach as Hackers Leak Filesbrinks homedata breachesSecurityWeekRecent SonicWall Vulnerabilities Exploited in Ransomware AttacksexploitedransomwarePalo Alto NetworksPass the Passkey: A Novel Attack Surface in Passwordless Authenticationgoogle authenticatorgoogle chromeAlienVaultA China-Nexus Campaign Against Government Infrastructurecobalt-strikecve-2025-24813SecurityWeekRussian State APT Linked to Recent Public Wi-Fi Gateway HackingaptmicrosoftAlienVaultA Deep Dive Into the Latest XCSSET Versionchrome hijackingdeveloper targetingAlienVaultReversing a Windows Kernel Driver RootkitcrackerdrvdkomCrowdstrikeCrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Acceleratesthreat hunting & intelElasticBenchmarking the Agentic SOC: How we evaluate LLMs for security workflowssecurity-labs
Sunday 2 August 2026
BleepingComputerCOLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theftcryptocurrency
Saturday 1 August 2026
BleepingComputerRails patches critical Active Storage flaw with RCE potentialSecurityWeekRuby on Rails Patches Critical Vulnerabilityrubyruby on rails
Friday 31 July 2026
ElasticElastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegassecurity-labsBleepingComputerAmgen says cloud data breach exposed patient health, proprietary infoBleepingComputerArch Linux disables AUR package adoption to stop malware floodBleepingComputerOnline ad firm Adform’s script compromised to steal cryptocurrencycryptocurrencyMicrosoftCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftadversary-in-the-middle (aitm)clickfixRecorded FutureCISA warns of spike in attacks on water systems as Minnesota incidents probedcybercrimegovernmentBleepingComputerHacker uses DeepSeek AI to autonomously attack vulnerable serversartificial intelligenceBleepingComputerCISA warns of cyberattacks disrupting U.S. water utilitiesSecurityWeekIn Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Researchartificial intelligencein other newsSecurityWeekCyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian HackersiranmalwareBleepingComputerESET tracks rise in malicious AI skills and adaptable malwareRecorded FutureAnthropic says its AI hacked real-world companies in three incidentsSecurityWeekGoogle AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Paceartificial intelligencechromePalo Alto NetworksThe Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Versionbrowser hijackingcredential theftSecurityWeekPrompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizationsartificial intelligenceanthropicSecurityWeekCareCloud Data Breach Impacts Over 350,000careclouddata breachesSecurityWeekCritical Code Execution Vulnerability Patched in TeamCityjetbrainspatchBleepingComputerAnthropic's Claude breached 3 orgs, uploaded PyPI malware during testsElasticExploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defendsecurity-labs
Thursday 30 July 2026
BleepingComputerSouth Korea fines telco giant KT $39 million for customer data breachSecurityWeekCISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCsics/otRecorded FutureSemiconductor chip titan Analog Devices reports data breachcybercrimeindustryBleepingComputerAmazon links Debug, Chalk NPM supply-chain attacks to North Korean hackersCisco TalosYou were onto something with “It’s the Climb,” Mileythreat source newsletterBleepingComputerShinyHunters claims Brinks Home breach, threatens to leak stolen dataBleepingComputerMicrosoft Teams vishing attacks lead to Chaos ransomware attacksBleepingComputerAnalog Devices discloses data breach, says operations unaffectedBleepingComputerAfter the Break-In: What Attackers Do Once They're Already InsideRecorded FutureNorth Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warncybercrimegovernmentAlienVaultOctLurk and SilkLurk: new Backdoors in Central Asiacentral asiacredential harvestingRecorded FutureNorth Korean hackers behind major open-source supply chain attacks, Amazon sayscybercrimemalwareSecurityWeekSemiconductor Firm Analog Devices Discloses Data Breachanalog devicesdata breachesAlienVaultTax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayersbanking credentialsfake government noticesAlienVaultXMRig Covert Ops: The Cryptomining Campaign That Abuses Trusted Access and Deploys Forensic Smokescreenscryptominingforensic evasionPalo Alto NetworksChinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattackschatgptclaude codeCisco TalosBlack Hat special: Rewind and revisithumans of talosSecurityWeekCritical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarmsartificial intelligencerufloAlienVaultToy Ghouls’ new toy: the GenieLocker ransomwarebabukbearlyfySecurityWeek1 in 5 Data Center Assets Are Within Easy Reach of Attackersclarotydata centerSecurityWeekChrome 151 Patches 370 VulnerabilitieschromepatchesSecurityWeekCisco Secure FMC Zero-Day Exploited in the WildciscoexploitedCrowdstrikeFalcon AIDR Now Protects Copilot Studio Agents and Claude Codesecuring ai
Wednesday 29 July 2026
BleepingComputerRussian hackers exploit Exchange OWA zero-day for long-term mailbox accessBleepingComputerCisco warns of FMC static credential flaw exploited in zero-day attacksAlienVaultReverse Engineering the Six Stages of MacSync Stealer and RATamosatomic stealerBleepingComputerHealth-ISAC warns of rising ShinyHunters data theft attacks on healthcareRecorded FutureOpenAI says rogue agent behind Hugging Face hack broke into additional servicescybercrimeBleepingComputerOpenAI agent used exposed credentials at 4 services in Hugging Face breachartificial intelligenceBleepingComputerHackers target over 30 Minnesota water utilities in coordinated OT attackRecorded FutureLaundry Bear’s webmail hackers had more in store after February, report sayscybercrimemalwareAlienVaultCleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploitcredential theftcve-2026-42897AlienVaultPhantom Stealer Unmasked: Shellcode, Steganography, and Credential Theftanti-analysisbrowser credential harvestingRecorded FutureRussia accuses Telegram founder of aiding terrorism, seeks international arrestgovernmentSecurityWeekCritical VM Escape Vulnerability Patched in VMware ESXipatchvmwareAlienVaultAnalysis of BlueShell Variants Used by APT Groupsanti-forensicaptAlienVaultDistributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developersalibabaaone-cliAlienVaultShai-Hulud-Style npm Worm Hits@tanstackawsSecurityWeekJFrog Zero-Days Exploited in OpenAI-Hugging Face Hackartificial intelligenceexploitedSecurityWeekDozens of Minnesota Water Utilities Targeted in Coordinated OT AttacksdisruptionicsSecurityWeekShinyHunters Claims Ernst & Young Hackdata breachesernst&youngCrowdstrikeInside Astaroth's New Spambot Componentthreat hunting & intelAlienVaultBotnet Rising Star: The Evolution and In-Depth Technical Analysis of Dysphoriablockchain c2botnetAlienVaultTwo Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojanblockchain loaderdev#popperAlienVaultClickFix Keeps Evolving: Rundll32 Ordinal Execution over WebDAVclickfixcredential theftElasticStop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is heresecurity-labs
Tuesday 28 July 2026
AlienVaultFlying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragonandroid ratbtmobBleepingComputerCISA shares advice on isolating vital systems during cyberattacksBleepingComputervBulletin fixes critical pre-auth RCE flaw with public exploitRecorded FutureIndia’s Bank of Baroda confirms cyber incident after hackers claim data theftcybercrimeindustrySecurityWeekApple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoeappleendpoint securityBleepingComputerIs Your SSO Protected Against Modern Credential Attacks?AlienVaultMirage Kitten targets Middle East and Africa region with new malwareafricaarcbridgeBleepingComputerOver 24,000 exposed server BMCs leak password hash via decades-old flawSecurityWeekHacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blockerhackerhacker conversationsSecurityWeekAct Security Emerges from Stealth to Fight the Patch Problemfundingfunding/m&aCisco TalosIR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chainscisco talos incident responsectir trendsBleepingComputerData breach at medical billing firm MCBS affects 1.26 million peoplehealthcareSecurityWeekGoogle Adopts New Threat Actor Naming SystemgooglemalwareSecurityWeekUnpatched Fastjson Vulnerability Exploited in AttacksexploitedfastjsonSecurityWeekCritical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-DayaristaexploitedSecurityWeekOrigin Energy Data Breach Affects 900,000 Australiansdata breachesenergyAlienVaultExpanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connectionboryptgrabbrowser extensionAlienVaultTechnical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Corebatch endpointcve-2026-60137SecurityWeekFor Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startupartificial intelligence
Monday 27 July 2026
BleepingComputerHackers target US firms in FastJson RCE zero-day attacksBleepingComputerArista patches VeloCloud Orchestrator zero-day exploited in attacksBleepingComputerNew Dysphoria DDoS botnet spreads to 200k devices worldwideBleepingComputerNew Certighost PoC exploit lets attackers hijack Windows domainsRecorded FutureUK court rejects Bahrain immunity claim in spyware casecybercrimegovernmentRecorded FutureHealth system in South Carolina, Georgia closes offices after malware affects networkscybercrimeAlienVaultAI-Native security platformai agent securityaws bedrockAlienVaultHelpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoorblinddoordata exfiltrationRecorded FutureHackers used Telegram phishing campaign to target exiled Belarusian activistcybercrimemalwareBleepingComputerCoca-Cola confirms data theft in Fairlife ransomware attackBleepingComputerErnst & Young data breach claimed by ShinyHunters extortion gangSecurityWeekNew GitHub, PyPI Policies Boost Supply Chain Securityapplication securitygithubSecurityWeekPTC Windchill Vulnerability Exploited in Ransomware Campaigncl0pexploitedSecurityWeekMedusaHVNC Malware Uses Hidden Windows Desktops to Evade DetectionmalwareRecorded FutureHackers used autonomous AI agent to spy on Thailand's finance ministrygovernmentmalwareSecurityWeekCoca-Cola Confirms Data Breach After Fairlife Ransomware Attackanubiscoca-colaSecurityWeekHacked Public Wi-Fi Gateways Used to Harvest Corporate Credentialsmalwaremicrosoft 365SecurityWeekAnthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploitsartificial intelligenceanthropicSecurityWeekDentaQuest Data Breach Potentially Impacts Over 23 Million Peopledata breachesdentaquestCrowdstrike5 High-Impact Use Cases for Falcon Onumnext-gen siem & log managementSecurityWeekMCBS Data Breach Affects 1.2 Million Individualsdata breacheshealthcareCrowdstrikeCrowdStrike Joins the Open Secure AI Alliance to Advance AI Safety and Securitysecuring aiElasticInside Elastic InfoSec's agentic SOC: How we cut AI agent LLM calls by 60%security-labs
Sunday 26 July 2026
BleepingComputerGitHub, PyPI add time-absed defenses against supply chain attacks
Saturday 25 July 2026
BleepingComputerSteam forum ClickFix attacks infect gamers with XMRig cryptominersBleepingComputerMalicious sites use JavaScript to build malware in browser memoryBleepingComputerShinyHunters data leaks fuel $2,000 sextortion email scamSecurityWeekRockwell Patches Code Execution Flaws in Arena Simulation Softwareicsics/otAlienVaultFake Corepack Site Distributes Infostealer and Proxyware to Developersapprunnercorepack impersonation
Friday 24 July 2026
AlienVaultCheck Point SmartConsole Authentication Bypass (CVE-2026-16232)authentication bypasscheck pointBleepingComputerOnTrac notifies customers of data breach after network hackBleepingComputerHermes AI agent used to automate attack on Thai Finance Ministry

Headlines and links are the property of their publishers and appear here as attributed links. Follow any headline to read the original.