Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.
Each item includes our perspective on why it matters to your security posture.
ExfilSquad dumps data on 100,000+ UK police and justice staff after a Microsoft Power Pages misconfiguration; 18 npm packages plant a cross-platform RAT in Alibaba developer tools; and INC Ransomware turns two SonicWall SMA 1000 zero-days into a credential and MFA-seed harvesting spree.
Read source →N-able's first fix for a critical N-central flaw proves incomplete as attackers keep admin access via hidden Cloudflare Tunnels; Anthropic discloses three Claude models breached real companies during misconfigured evaluations; and Russia's Midnight Blizzard hijacks hotel Wi-Fi to plant the CornFlake RAT.
Read source →Unit 42 details a China-based actor wiring DeepSeek into an open-source agent framework to run exploitation autonomously; Amgen discloses a material cloud breach exposing patient PHI; Broadcom patches three critical VMware flaws including a 9.8-CVSS vCenter auth bypass; and a poisoned Adform ad script hijacks cryptocurrency wallet addresses across customer sites.
Read source →Kaspersky exposes OctLurk and SilkLurk, memory-resident backdoors hitting Central Asian governments; Wiz details CosmosEscape, a now-patched flaw that exposed a platform-wide key to every Azure Cosmos DB tenant; CISA warns of a nationwide surge in attacks on internet-exposed water utility PLCs; and Arch Linux halts AUR package adoptions to stop a supply-chain malware campaign.
Read source →A public proof-of-concept lands for an actively exploited Check Point SmartConsole authentication bypass, a critical DHCPv6 flaw threatens root compromise on OpenWrt routers, over 24,000 exposed server management interfaces leak password hashes via a 22-year-old IPMI flaw, and a 7-Zip archive bug adds crafted XZ files to the code-execution watch list.
Read source →A coordinated cyberattack knocks a Minnesota water plant offline and disrupts 30+ community systems, a critical Rails flaw lets attackers read server secrets through ordinary image uploads, Cisco's hardcoded FMC credentials land in CISA's KEV catalog under an August 1 deadline, and a leaked Android RAT framework is already running on 170 servers.
Read source →Origin Energy confirms a breach touching roughly 900,000 customer accounts, Termite ransomware affiliate Velvet Tempest is caught staging attacks with ClickFix and a CastleRAT backdoor, an actively exploited Arista VeloCloud Orchestrator zero-day lands in CISA's KEV catalog, AI helps a researcher turn a Linux kernel race condition into a root exploit, and JetBrains patches an unauthenticated RCE in TeamCity before anyone finds it first.
Read source →Coca-Cola confirms the Anubis ransomware gang stole data from its Fairlife dairy unit, RansomHouse's extortion of Japan's largest cold-chain logistics operator ripples into KFC Japan's menu, a Telegram-based backdoor surfaces in attacks on Middle East governments, and a public exploit lands for a pre-auth vBulletin RCE.
Read source →South Korea discloses a ten-month breach of its diplomatic academy's training system, a researcher escapes Claude Cowork's Linux VM to read Mac host files, a phishing link could forge a rogue autonomous agent inside any ChatGPT Workspace, and a race condition in Ubuntu's snap-confine hands local users root.
Read source →SonicWall's SMA1000 zero-days have been under active exploitation since June, a public PoC lets any GitLab contributor run commands as git through a notebook-diff heap bug, a threat actor ran the Hermes AI agent unattended against Thailand's Finance Ministry, and Anubis ransomware gives Coca-Cola's Fairlife until tomorrow before leaking 1TB of stolen data.
Read source →