Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Attack TTPs combine fileless execution, wide LOLBin useCategories: Threat Research
Lures on compromised WordPress sites led to installation of Deno and a Python-based infostealerCategories: Threat ResearchTags: clickfix, Deno, WordPress
Minerals become chips. Chips become data centers. Data centers become models, and models are acquiring arms and legs. From Earth to Embodied AI traces the supply chain of the fourth industrial revolution, and shows how geopolitical rivalry and cyber operations now run along every link, from mine to machine.
This week on the Lock and Code podcast, we speak with Chris Parr about his inventive and all-too-funny stress-test of surveillance pricing.
Solana is a crypto platform known for speed. Developers like it to develop distributed applications or to implement crypto payments. To interact with the blockchain, APIs are provided for developers. These APIs will either "speak" JSON or gRPC. One implementation often used for development is "surfpool," which is used to test programs before deploying them to a Solana network.
We discovered a kit that gave us an insight into how modern online scams are built, promoted, and potentially used to target everyday consumers.
Microsoft is retiring Manifest V2, the technology behind older Edge extensions. Some popular privacy tools will lose features or stop working.
AI tutors can offer useful support, but their quality and safeguards vary widely. Here’s what parents should check before handing one to a child.
A list of topics we covered in the week of August 3 to August 9 of 2026
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
The Hugging Face and OpenAI security incident showed AI doesn't make attackers smarter. It makes persistence cheap, and defenses built for alerts can't keep up.
Chat bots are sending friend requests in Riot immediately after ending your game. What are the scammers up to now?
A new court ruling not only fined Meta to the extent of $942 million but also ordered it to improve its age assurance tools.
A new court ruling not only fined Meta to the extent of $942 million but also ordered it to improve its age assurance tools.
UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they definitely lack of "modern" logging: shells. Most shells provide an historization of the typed commands through a flat file in the $HOME directory (ex: $HOME/.bash_history). They suffer of multiple problems:
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
In July 2026, Insikt Group® identified 85 high-impact vulnerabilities that should be prioritized for remediation, 36 of which had a Very Critical Recorded Future Risk Score. This represents a 44% increase from last month.
In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat.
Researchers have found three methods to bypass Apple's Private Relay which is supposed to shield users' IP addresses and location.
Criminals are impersonating OnlyFans creators using AI tools in order to scam followers.
Different logos, different color schemes, same scam.
Testers found that Anthropic's AI agent Mythos attempted to social engineer Github developers into accepting malicious code.
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
[This is a Guest Diary by Daryl Jiminez, an ISC intern as part of the SANS.edu BACS program]
Explore the evolving security landscape of neurotechnology, including risks like IP theft, data extortion, and regulatory challenges in this emerging field.
When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In the keyv/cacheable compromise that has been unfolding since yesterday, it is the one thing you should not do first — because revoking the stolen token is exactly what arms the payload.
Over time, passkeys are supposed to replace passwords. But what happens when malware steals the master key?
The easiest way to reclaim storage on your phone. Free up space without hunting through folders or risking your important files.
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.