News

Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)

Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897) 2026-07-30 at 17:23 By Zeljka Zorz Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange, to target US and European government entities and a variety of private sector organizations via email. The

Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897) Read More »

CISA sets a new SBOM baseline

CISA sets a new SBOM baseline 2026-07-30 at 15:23 By Anamarija Pogorelec The US Cybersecurity and Infrastructure Security Agency (CISA), together with its co-authoring partners, has released the 2026 Minimum Elements for a Software Bill of Materials (SBOM), replacing the 2021 guidance published by the National Telecommunications and Information Administration (NTIA). An SBOM is a

CISA sets a new SBOM baseline Read More »

Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks

Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks 2026-07-30 at 14:22 By Sinisa Markovic Attackers are moving away from fake Microsoft login pages in favor of abusing Microsoft’s own authentication system, letting phishing campaigns slip past the warning signs employees are trained to spot, according to Check Point. Between June 25 and

Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks Read More »

Cisco FMC static credentials exploited by attackers (CVE-2026-20316)

Cisco FMC static credentials exploited by attackers (CVE-2026-20316) 2026-07-30 at 13:44 By Zeljka Zorz A static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), a platform for centrally managing multiple Cisco Secure Firewall devices across a network, is being leveraged by attackers, CISA warned. Two FMC flaws, one indicator of compromise CVE-2026-20316, reported

Cisco FMC static credentials exploited by attackers (CVE-2026-20316) Read More »

Coordinated cyberattack hits more than 30 Minnesota water utilities

Coordinated cyberattack hits more than 30 Minnesota water utilities 2026-07-30 at 11:59 By Sinisa Markovic A coordinated cyberattack on July 26 and 27 hit operational technology (OT) systems at more than 30 community water utilities across Minnesota, prompting an immediate response from Minnesota IT Services (MNIT) to contain the threat. MNIT confirmed the attack in

Coordinated cyberattack hits more than 30 Minnesota water utilities Read More »

Data breach cost 2026 averaged $4.99 million, AI attacks ran higher

Data breach cost 2026 averaged $4.99 million, AI attacks ran higher 2026-07-30 at 09:15 By Mirko Zorz More than one in four organizations hit by a malicious attack over the past year say AI drove it. Those breaches averaged about $1 million above the malicious attacks that ran without AI. Defenders bought similar technology and

Data breach cost 2026 averaged $4.99 million, AI attacks ran higher Read More »

200 new CVEs a day and no realistic way to patch them all

200 new CVEs a day and no realistic way to patch them all 2026-07-30 at 09:00 By Mirko Zorz Ryan Dewhurst, CEO at KEVIntel, explains how his team confirms exploitation that CISA’s catalog has not listed yet. He describes a global honeypot sensor network, AI triage, and human verification in a lab before a vulnerability

200 new CVEs a day and no realistic way to patch them all Read More »

Top companies to visit at Black Hat USA 2026

Top companies to visit at Black Hat USA 2026 2026-07-30 at 08:30 By Mirko Zorz Black Hat USA 2026 returns to Mandalay Bay with a re-engineered six-day program designed to spark innovation, challenge assumptions, and unite the global security community. The event opens with four days of immersive, expert-led Trainings (August 1-4), continues with Summit

Top companies to visit at Black Hat USA 2026 Read More »

Impersonation protection: How to protect your executives when the truth isn’t clear

Impersonation protection: How to protect your executives when the truth isn’t clear 2026-07-30 at 08:00 By Help Net Security How do you protect your executives when truth doesn’t seem to be truth anymore? It’s a question BlackCloak Founder and CEO Dr. Chris Pierson recently discussed this dilemma with SVP of Product Matt Covington. Advances in

Impersonation protection: How to protect your executives when the truth isn’t clear Read More »

Product showcase: Dashlane Password Manager is more security toolkit than password vault

Product showcase: Dashlane Password Manager is more security toolkit than password vault 2026-07-30 at 07:30 By Anamarija Pogorelec Dashlane is a password manager for individuals and families that stores passwords, passkeys, payment cards, personal information and secure notes in an encrypted vault. It also includes a password generator, password health reports, an authenticator, credential sharing,

Product showcase: Dashlane Password Manager is more security toolkit than password vault Read More »

Exposed credentials are giving attackers a head start many organizations don’t see

Exposed credentials are giving attackers a head start many organizations don’t see 2026-07-30 at 07:00 By Anamarija Pogorelec Compromised credentials can remain active long after passwords are created, leaving organizations trying to identify exposed accounts before attackers can use them. The 2026 Credential Risk Report from Enzoic shows growing awareness of the problem, but monitoring

Exposed credentials are giving attackers a head start many organizations don’t see Read More »

Tengu botnet reboots Linux devices to survive removal

Tengu botnet reboots Linux devices to survive removal 2026-07-29 at 16:52 By Sinisa Markovic A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found. The malware, dubbed Tengu, was discovered by a

Tengu botnet reboots Linux devices to survive removal Read More »

ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility

ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility 2026-07-29 at 16:00 By Help Net Security Research from Aryon reveals that each year, 3,731,699 short-lived cloud resources containing highly sensitive information are publicly exposed. This impacts any organization using AWS services that support public sharing. These exposures often last only minutes or hours,

ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility Read More »

Cloudflare reveals what’s behind major internet outages

Cloudflare reveals what’s behind major internet outages 2026-07-29 at 13:20 By Sinisa Markovic Storms, earthquakes, and infrastructure failures disrupted internet access throughout the second quarter, while governments deliberately shut networks down, according to Cloudflare’s latest Internet Disruption Summary. Based on Cloudflare Radar traffic data, the report covers internet disruptions recorded between April and June 2026.

Cloudflare reveals what’s behind major internet outages Read More »

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced 2026-07-29 at 08:30 By Mirko Zorz A ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to bring them online meets

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced Read More »

Specter: Open-source NFC reader bug sweep for Flipper Zero

Specter: Open-source NFC reader bug sweep for Flipper Zero 2026-07-29 at 08:00 By Anamarija Pogorelec Specter is a Flipper Zero app that finds powered NFC readers by listening for the radio field they give off. The readers it hunts work at 13.56 MHz. The Flipper’s own chip does the sensing The onboard ST25R3916 carries a

Specter: Open-source NFC reader bug sweep for Flipper Zero Read More »

Your AI agents can reach data no one approved

Your AI agents can reach data no one approved 2026-07-29 at 07:30 By Mirko Zorz A credential expired. An AI agent kept using it anyway, and a mid-sized company’s systems went down for a quarter’s worth of trouble before anyone traced the failure back to a non-human account no one had been logging. That agent

Your AI agents can reach data no one approved Read More »

Android malware detection collapses when the context stage comes out

Android malware detection collapses when the context stage comes out 2026-07-29 at 07:00 By Anamarija Pogorelec A phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine learning malware scanner and it comes back flagged. Six Android detectors in wide

Android malware detection collapses when the context stage comes out Read More »

Hugging Face breach reignites open-weights debate, raises liability questions

Hugging Face breach reignites open-weights debate, raises liability questions 2026-07-28 at 18:55 By Zeljka Zorz The first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident post-mortem compiled with the input from Hugging Face and several hundred members of

Hugging Face breach reignites open-weights debate, raises liability questions Read More »

Scroll to Top