Cybersecurity and other IT news aggregator

LATEST FEEDS

  • Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

    Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities 2026-08-06 at 15:16 By Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844…


  • CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

    CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps 2026-08-06 at 14:49 By Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains. Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet apps used to generate recovery…


  • Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

    Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses 2026-08-06 at 14:33 By Cybersecurity researchers have disclosed a security issue with Apple’s iCloud Private Relay tool that can expose a user’s real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users’ privacy by routing their…


  • AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory

    AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory 2026-08-06 at 14:30 By A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links. We observed production…


  • Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison

    Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison 2026-08-06 at 12:30 By Ionut Arghire Maksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution. The post Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View…


  • Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

    Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access 2026-08-06 at 12:19 By Attackers broke into an organization’s Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle…


  • Block raises 2026 outlook on strong quarter, says AI touches nearly all code

    Block raises 2026 outlook on strong quarter, says AI touches nearly all code 2026-08-06 at 04:33 By Cointelegraph by Felix Ng Cash App and Square drove better-than-expected results, while the company said it expanded its use of AI across software engineering. This article is an excerpt from Cointelegraph.com News View Original Source


  • Mysten Labs tech chief joins Anthropic to work on AI security

    Mysten Labs tech chief joins Anthropic to work on AI security 2026-08-06 at 04:31 By Cointelegraph by Felix Ng Mysten Labs’ co-founder Sam Blackshear said he is joining Anthropic as AI shifts the balance between attackers and defenders. This article is an excerpt from Cointelegraph.com News View Original Source


  • Bitcoin Red Team reports 5K findings in sweeping security audit

    Bitcoin Red Team reports 5K findings in sweeping security audit 2026-08-06 at 04:09 By Cointelegraph by Felix Ng “There’s a lot of chaos right now in the ecosystem. We absolutely understand that many people are being bombarded with security issues right now,” said Bitcoin developer Calle. This article is an excerpt from Cointelegraph.com News View…


  • Google’s Jeff Dean — chief scientist for 27 years — leaving during AI leadership overhaul for startup

    Google’s Jeff Dean — chief scientist for 27 years — leaving during AI leadership overhaul for startup 2026-08-06 at 03:07 By Taylor Herzlich Google’s current chief scientist is leaving to start his own AI startup, Discovery Loop, with three other company veterans, according to a company blog post. This article is an excerpt from Latest…


  • Bloodbath at Visa as top execs making mega bucks get canned from California offices

    Bloodbath at Visa as top execs making mega bucks get canned from California offices 2026-08-06 at 00:27 By Titus Wu Payment processing giant brutally cut 2,600 jobs, sparing no one — not even top executives. This article is an excerpt from Latest Technology News | New York Post View Original Source


  • Senator Warren questions US AI chip policy after Trump crypto investment: Report

    Senator Warren questions US AI chip policy after Trump crypto investment: Report 2026-08-06 at 00:15 By Cointelegraph by Turner Wright The lawmaker reportedly sent a letter to the Commerce Secretary demanding answers about the administration’s treatment of the UAE following investments in the Trump family’s crypto company. This article is an excerpt from Cointelegraph.com News…


  • Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

    Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt 2026-08-05 at 23:27 By Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access to Anthropic’s large language models…


  • Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

    Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports 2026-08-05 at 23:27 By Two security flaws in Paperclip could let attackers execute commands on a network server or a developer’s computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious…


  • How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones 

    How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones  2026-08-05 at 22:40 By Eduard Kovacs The chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications. The post How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek…


  • Senator Lummis still pushing for CLARITY vote before August recess

    Senator Lummis still pushing for CLARITY vote before August recess 2026-08-05 at 22:18 By Cointelegraph by Turner Wright US lawmakers have only a few days to hold a vote on a crypto market structure bill before a recess begins that could push consideration into the 2026 election season or beyond. This article is an excerpt…


  • Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers

    Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers 2026-08-05 at 21:45 By Mirko Zorz An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker runs code on the host. Bonita BPM handles…


  • Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

    Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures 2026-08-05 at 21:44 By A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The server-side gate…


  • OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

    OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes 2026-08-05 at 21:33 By OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of…


  • Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses

    Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses 2026-08-05 at 18:55 By Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized…


  • Release the RAVEN: First Contact

    Release the RAVEN: First Contact 2026-08-05 at 18:11 By Karl Biron You are mid-engagement. Nmap finishes its sweep and port 9200 lights up on a host. Elasticsearch. You know it matters. You know the client’s logging pipeline, search infrastructure, or analytics platform probably flow through it. But what do you actually know about this cluster?…


  • Gold hits six-week highs on China demand as Bitcoin ignores fresh S&P 500 record

    Gold hits six-week highs on China demand as Bitcoin ignores fresh S&P 500 record 2026-08-05 at 18:02 By Cointelegraph by William Suberg Gold and US stocks stole the limelight on Wednesday as Bitcoin failed to gain significantly beyond $64,000. This article is an excerpt from Cointelegraph.com News View Original Source


  • Top product launches at Black Hat USA 2026

    Top product launches at Black Hat USA 2026 2026-08-05 at 18:00 By Anamarija Pogorelec Black Hat USA 2026 is underway in Las Vegas, and vendors are using the moment to unveil what they hope will define the next year of defense. Here are the announcements drawing the most attention on the ground, and why they…


  • Black Hat USA 2026 – Summary of Vendor Announcements (Part 3)

    Black Hat USA 2026 – Summary of Vendor Announcements (Part 3) 2026-08-05 at 17:36 By SecurityWeek News Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 3) appeared first on…


  • Stellar Cyber’s Auto-Triage AI matches human analysts 99.7% of the time

    Stellar Cyber’s Auto-Triage AI matches human analysts 99.7% of the time 2026-08-05 at 17:30 By Industry News Stellar Cyber, the full-cycle AI-native security operations platform company, today released results from an independent study of 124 days of customer trials of its Agentic Auto Triage capability. The independent study based on customer trials evaluated 138,475 real…


  • Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

    Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug 2026-08-05 at 17:27 By HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam’s console that hands over a managed agent’s credentials,…


  • From Stolen Credentials to Full Breach: The 72-Hour Timeline

    From Stolen Credentials to Full Breach: The 72-Hour Timeline 2026-08-05 at 17:26 By Ashish Khaitan A single compromised credential is often all it takes to turn an ordinary workday into a full-scale cybersecurity incident. Despite investments in firewalls, endpoint security, and identity controls, attackers continue to exploit one of the simplest yet most effective entry points—stolen…


  • Crypto whales accumulate as bear market nears late stage: CryptoQuant

    Crypto whales accumulate as bear market nears late stage: CryptoQuant 2026-08-05 at 17:08 By Cointelegraph by Helen Partz Bitcoin, Ethereum and XRP whales increased balances during market weakness, as CryptoQuant said large holders are absorbing supply ahead of a possible bottom. This article is an excerpt from Cointelegraph.com News View Original Source


  • Do the Coldcard attacks mean all hardware wallets are now insecure?

    Do the Coldcard attacks mean all hardware wallets are now insecure? 2026-08-05 at 16:30 By Cointelegraph by Christina Comben The Coldcard entropy flaw caused a crisis of confidence in hardware wallets. Here’s the details you need to know before you entrust Ledger, Trezor or Foundation with your Bitcoin. This article is an excerpt from Cointelegraph.com…


  • Galaxy reports $85M net loss amid Q2 crypto market slump

    Galaxy reports $85M net loss amid Q2 crypto market slump 2026-08-05 at 16:20 By Cointelegraph by Zoltan Vardai Galaxy Digital reported an $85 million net loss driven by falling digital asset prices and $8.7 billion in revenue that missed Wall Street estimates. This article is an excerpt from Cointelegraph.com News View Original Source


  • Tenable broadens AI visibility across major LLMs and AI tools

    Tenable broadens AI visibility across major LLMs and AI tools 2026-08-05 at 16:16 By Industry News Tenable has announced enhanced AI security capabilities within the Tenable One Exposure Management Platform. Tenable One AI Exposure now delivers expanded platform coverage with support for Google Gemini, extending its coverage across major LLMs: Google Gemini, Anthropic Claude, OpenAI…


  • Lumu launches live threat intelligence platform for real-time cyber defence

    Lumu launches live threat intelligence platform for real-time cyber defence 2026-08-05 at 16:15 By Industry News Lumu has announced the release of Lumu Threat Observatory as part of Maltiverse, its threat intelligence solution. Lumu Threat Observatory is Maltiverse’s live, personalized threat-intelligence experience, providing organizations with a complete, live view of the active threats targeting their…


  • ArmorCode enhances attack path analysis with new AI agents and Context Risk Graph

    ArmorCode enhances attack path analysis with new AI agents and Context Risk Graph 2026-08-05 at 16:07 By Industry News ArmorCode has announced a major expansion of its Agentic Control Plane. Four new Anya AI agents help security teams analyze cloud risks, assess vulnerability exploitability, identify mitigation strategies, and coordinate patch orchestration. It also unveiled new…


  • The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict

    The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict 2026-08-05 at 16:00 By Kevin Townsend CrowdStrike co-founder Dmitri Alperovitch discusses how cyber operations support kinetic warfare, signal coming conflicts, and reshape the global battlefield. The post The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict appeared first on SecurityWeek.…


  • Mastercard, Borderless test shared identity checks for stablecoin transfers

    Mastercard, Borderless test shared identity checks for stablecoin transfers 2026-08-05 at 16:00 By Cointelegraph by Zoltan Vardai Mastercard and Borderless are exploring ways to bring more trust into cross-border stablecoin transfers through the payment processing giant’s Crypto Credential framework. This article is an excerpt from Cointelegraph.com News View Original Source


  • Tuskira expands exposure management with Agentic Control Plane

    Tuskira expands exposure management with Agentic Control Plane 2026-08-05 at 15:54 By Industry News Tuskira has launched its Agentic Control Plane for Exposure Management, a new capability within the Tuskira platform that governs AI-discovered vulnerabilities from scan to verified closure. The capability extends Tuskira’s existing zero-day and exposure-response capabilities to frontier-model scanning. Tuskira applies enterprise…


  • New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts

    New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts 2026-08-05 at 15:48 By Eduard Kovacs Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation. The post New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Circle Q2 revenue falls short of Wall Street estimates

    Circle Q2 revenue falls short of Wall Street estimates 2026-08-05 at 15:47 By Cointelegraph by Zoltan Vardai Stablecoin issuer Circle reported $701 million in Q2 revenue, missing Wall Street estimates of about $713 million. This article is an excerpt from Cointelegraph.com News View Original Source


  • New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

    New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch 2026-08-05 at 15:47 By A memory corruption flaw in the Linux kernel’s Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel…


  • Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

    Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk 2026-08-05 at 15:47 By Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft’s real authentication page. Once access and refresh tokens are issued, attackers may retain…


  • INTERPOL flags AI as the new engine of African cybercrime

    INTERPOL flags AI as the new engine of African cybercrime 2026-08-05 at 15:24 By Anamarija Pogorelec Africa’s growing digital economy is exposing governments, businesses and internet users to a rising wave of cybercrime. The continent recorded more than 1.1 billion mobile subscriptions and over $1.1 trillion in digital transactions in 2025, while more than 570…


  • AI agent deception moves from theory to reality in UK cyber tests

    AI agent deception moves from theory to reality in UK cyber tests 2026-08-05 at 15:05 By Zeljka Zorz “During a routine cyber evaluation, AI agents took sustained, unsanctioned action directed at real people and organisations,” UK’s AI Security Institute (AISI) disclosed on Tuesday. The agents’ actions included an attempted supply-chain attack that saw them create…


  • Binance sues RedotPay over alleged $473 million user losses: Report

    Binance sues RedotPay over alleged $473 million user losses: Report 2026-08-05 at 15:01 By Cointelegraph by Helen Partz Binance-linked companies sued RedotPay, accusing it of diverting more than 470,000 Binance Card users under a commercial deal and seeking nearly $473 million in damages. This article is an excerpt from Cointelegraph.com News View Original Source


  • Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

    Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data 2026-08-05 at 14:52 By A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The “evil twin” extensions were uploaded to the…


  • 311,000 Impacted by Brown Health Medical Group-MA Data Breach

    311,000 Impacted by Brown Health Medical Group-MA Data Breach 2026-08-05 at 14:35 By Ionut Arghire Hackers stole personal information, medical records, and financial information from the organization’s server. The post 311,000 Impacted by Brown Health Medical Group-MA Data Breach appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Code review used to be the only way to catch these bugs

    Code review used to be the only way to catch these bugs 2026-08-05 at 14:30 By Mirko Zorz An automated system called NOVA read the source code of 3,915 open-source projects over two months and came back with 14,090 vulnerabilities, each one confirmed through the system’s validation pipeline. Vulnerability researchers at Palo Alto Networks’ Unit…


  • Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data 

    Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data  2026-08-05 at 14:11 By Eduard Kovacs The guidelines are the work of the recently launched Open Secure AI Alliance, which now includes 120 organizations. The post Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data  appeared first on SecurityWeek. This article is an excerpt…


  • Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

    Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup 2026-08-05 at 14:04 By An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The…


  • Bitcoin ETFs log inflows as cold wallet hack reignites custody debate

    Bitcoin ETFs log inflows as cold wallet hack reignites custody debate 2026-08-05 at 13:43 By Cointelegraph by Helen Partz US spot Bitcoin ETFs drew $382 million in two-day inflows, with Galaxy’s Bitcoin ETF returning to gains as the Coldcard incident renewed custody concerns. This article is an excerpt from Cointelegraph.com News View Original Source


  • S&P gives BlackRock tokenized reserve fund top stability rating

    S&P gives BlackRock tokenized reserve fund top stability rating 2026-08-05 at 13:40 By Cointelegraph by Zoltan Vardai The rating recognizes the fund’s ability to maintain a stable net asset value, while S&P separately reaffirmed USDT among the lowest-rated stablecoins under its existing assessment framework. This article is an excerpt from Cointelegraph.com News View Original Source


Browse older archives

Scroll to Top