News

Code review used to be the only way to catch these bugs

Code review used to be the only way to catch these bugs 2026-08-05 at 14:30 By Mirko Zorz An automated system called NOVA read the source code of 3,915 open-source projects over two months and came back with 14,090 vulnerabilities, each one confirmed through the system’s validation pipeline. Vulnerability researchers at Palo Alto Networks’ Unit […]

Code review used to be the only way to catch these bugs Read More »

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic 2026-08-05 at 12:35 By Mirko Zorz TP-Link prints the serial number of an Omada router on its packaging and on a label attached to the device. Those numbers run in sequence, and feeding a guessed one to the Omada cloud service returns the

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic Read More »

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove 2026-08-05 at 11:43 By Zeljka Zorz A phishing campaign impersonating Bank of America (BoA) is underway, trying to trick Windows users into installing ScreenConnect remote access software and then making it difficult to uninstall it. Different traps for Mac and Windows users By

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove Read More »

Cloudflare gives AI agents wallets with built-in spending controls

Cloudflare gives AI agents wallets with built-in spending controls 2026-08-05 at 10:54 By Anamarija Pogorelec Cloudflare’s Wallets will give AI agents running on its platform a human-readable wallet handle for paying APIs and online content within limits set by their creator. Handle reservations have opened, while the service will become available in the coming months.

Cloudflare gives AI agents wallets with built-in spending controls Read More »

Future AGI: Open-source platform for shipping self-improving AI agents

Future AGI: Open-source platform for shipping self-improving AI agents 2026-08-05 at 08:30 By Anamarija Pogorelec Future AGI is an open-source platform for tracing, evaluating, simulating, and guardrailing LLM agents, licensed Apache 2.0 and self-hostable. Self-hosted instances register with Future AGI on first boot and send an instance ID, a version string, a deployment type, and

Future AGI: Open-source platform for shipping self-improving AI agents Read More »

Product showcase: Material unifies Google Workspace email, file & OAuth defense

Product showcase: Material unifies Google Workspace email, file & OAuth defense 2026-08-05 at 08:00 By Help Net Security Here’s an uncomfortable truth: the attack that gets you won’t look like an attack. It’ll look like a normal login, a normal file share, a normal permission request you clicked past without reading. You don’t have a

Product showcase: Material unifies Google Workspace email, file & OAuth defense Read More »

What stops attackers wrecking industrial plants is knowing how

What stops attackers wrecking industrial plants is knowing how 2026-08-05 at 07:30 By Mirko Zorz Engineers at an Israeli food producer spent most of a week rebuilding a refrigeration system after an intruder switched the gas cooler and receiver valves to manual and pinned them open. Liquid CO2 flooded the compressors and destroyed them. The

What stops attackers wrecking industrial plants is knowing how Read More »

Your enterprise AI footprint is about three times bigger than your model list

Your enterprise AI footprint is about three times bigger than your model list 2026-08-05 at 07:00 By Anamarija Pogorelec Organizations are building AI systems that combine models, agents and external tools instead of relying on standalone AI, according to Snyk’s latest State of Agentic AI Adoption report. The study analyzed 3,044 enterprise environments and 1.39

Your enterprise AI footprint is about three times bigger than your model list Read More »

AI developers targeted via trojanized GitHub repositories

AI developers targeted via trojanized GitHub repositories 2026-08-04 at 17:10 By Sinisa Markovic Cybercriminals are cloning popular GitHub repositories for AI tools and developer resources to distribute an infostealer, according to Netskope Threat Labs. (Source: Netskope) Netskope came across the campaign while tracking a Windows-based MaaS infostealer, first reported in April 2026, that was spread

AI developers targeted via trojanized GitHub repositories Read More »

Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems

Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems 2026-08-04 at 16:20 By Nikita Kazymirskyi In light of the water-sector activity described below, we’ve increased monitoring for related indicators of compromise across our client environments. Please contact your LevelBlue account team with questions specific to your environment. This article is an excerpt

Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems Read More »

Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware

Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware 2026-08-04 at 13:45 By Sinisa Markovic Midnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at places like hotels and conference centers, according to new findings from Microsoft

Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware Read More »

Tanium expands autonomous security across AI, exposure management and SecOps

Tanium expands autonomous security across AI, exposure management and SecOps 2026-08-04 at 12:17 By Industry News Tanium has announced a series of new autonomous security capabilities across the Tanium Autonomous IT Platform. Spanning agentic AI, exposure management and security operations, the capabilities empower IT and security operators to stay ahead of an AI-accelerated threat landscape,

Tanium expands autonomous security across AI, exposure management and SecOps Read More »

Microsoft shortens NuGet API key lifetime to improve supply chain security

Microsoft shortens NuGet API key lifetime to improve supply chain security 2026-08-04 at 11:30 By Anamarija Pogorelec Microsoft is reducing the lifetime of new NuGet.org API keys from 365 days to 30 days starting August 17, 2026, to improve the security of NuGet, its package repository for .NET developers. API keys created before August 17

Microsoft shortens NuGet API key lifetime to improve supply chain security Read More »

EU begins enforcing AI Act, putting AI models under the microscope

EU begins enforcing AI Act, putting AI models under the microscope 2026-08-04 at 09:49 By Sinisa Markovic Europe’s fight to regulate AI models moved from paper to practice on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. On the same date, new transparency rules took effect,

EU begins enforcing AI Act, putting AI models under the microscope Read More »

Digital executive protection is a strategic imperative for CEOs

Digital executive protection is a strategic imperative for CEOs 2026-08-04 at 09:00 By Mirko Zorz In this interview with Help Net Security, Brian Hill, Field CISO, Client Advisory for BlackCloak, explains how attackers reach companies through the personal lives of executives. He describes a case where a draft report sat in an executive’s personal email

Digital executive protection is a strategic imperative for CEOs Read More »

OWASP’s subtractive security project measures the attack paths you erased

OWASP’s subtractive security project measures the attack paths you erased 2026-08-04 at 08:30 By Mirko Zorz An attacker who talks a user into opening an attachment gets whatever that machine still permits: a service account with rights across the domain, an outbound route to anywhere, a scripting engine sitting there for the taking. Christopher Frenz

OWASP’s subtractive security project measures the attack paths you erased Read More »

Analysts got 19 minutes back every hour in Stellar Cyber’s agentic auto triage trials

Analysts got 19 minutes back every hour in Stellar Cyber’s agentic auto triage trials 2026-08-04 at 08:00 By Mirko Zorz An analyst opening a queue on Monday morning will spend most of it on tickets that amount to nothing. Stellar Cyber’s Agentic Auto Triage closed 8,047 of those tickets on its own during customer trials,

Analysts got 19 minutes back every hour in Stellar Cyber’s agentic auto triage trials Read More »

Fake IRS letters direct crypto holders to bogus compliance portal

Fake IRS letters direct crypto holders to bogus compliance portal 2026-08-04 at 07:30 By Sinisa Markovic Scammers are sending physical letters to cryptocurrency holders that copy the look of official IRS notices. The letters tell recipients they must enroll in something called a Digital Asset Compliance Portal before a deadline, or risk penalties. “If you

Fake IRS letters direct crypto holders to bogus compliance portal Read More »

Cybersecurity jobs available right now: August 4, 2026

Cybersecurity jobs available right now: August 4, 2026 2026-08-04 at 07:00 By Anamarija Pogorelec Application Security Engineer Arcadia | USA | Remote – View job details As an Application Security Engineer, you will lead the application vulnerability management process by prioritizing and driving remediation of security findings. You will integrate and automate security tools within

Cybersecurity jobs available right now: August 4, 2026 Read More »

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577) 2026-08-03 at 17:33 By Zeljka Zorz Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution widely used by managed service providers, to gain access to managed endpoints. How the flaw was discovered “On July 31, 2026,

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577) Read More »

Scroll to Top