Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
Discover the security lessons from the recent incident where autonomous AI agents breached Hugging Face infrastructure.
Apple is fighting another attempt by the UK's Home Office to get a backdoor providing access to encrypted iCloud data.
This morning, I noticed specific sources "hunting" for vulnerabilities in URLs that I haven't noticed before. All of these URLs appear to be associated with diagnostic tools:
Russian cybercrime groups are running a campaign that abuses hospitality Wi-Fi to steal information from travelers worldwide.
Google has walked back an AI feature that allowed users to generate artificial images inside Google Earth, after a predictable flurry of deepfakes.
Talos has collected prompt logs from threat actor endpoints running various applications, such as Claude Code, CodeX, Cursor, or Gemini. This blog is an analysis of the ways we've seen bad actors leveraging cloud-based AI.
Scammers are trying to take over WhatsApp accounts by sending messages asking people to vote for a friend in a fake online contest.
ISC Stormcast For Tuesday, August 4th, 2026 https://isc.sans.edu/podcastdetail/10036, (Tue, Aug 4th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
<p>Multiple legitimate DFIR tools abused by GOLD EMBRACE double-extortion specialists</p>Categories: Threat Research
After compromising systems via CVE-2026-18577, threat actors use the additional RMM tools and network tunnels to establish persistent remote accessCategories: Threat ResearchTags: RMM, N-able, vulnerability
That "free" adult TikTok site could leave you with spam, unwanted apps, or fake verification fees.
The European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumer‑facing AI.
California has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all registered data brokers.
Register for an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents Talos IR faced in Q2.
A list of topics we covered in the week of July 27 to August 2 of 2026
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Explore eight key ways that AI is reshaping the threat intelligence landscape, from creating speed and stealth advantages for adversaries to helping defenders better prioritize threats and allocate resources.
Introduction
Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.
Scammers are using fake V-Bucks offers and locker value sites to hijack Fortnite accounts.
OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat made for a packed July roundup
Researchers have uncovered a new campaign that spreads the AtlasRAT remote access Trojan by disguising it as a Flash Player installer.
I was asked for help with a problem similar to the following.
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Amy hikes Virginia’s most difficult trail and muses on the persistent challenges of cybersecurity. The two aren't dissimilar.
Install Malwarebytes for Windows from the Microsoft Store with the same full protection and features.
The FTC has sued telehealth provider Hims & Hers, alleging it shared customers' sensitive health information with advertisers.
A new type of attack can trick Microsoft Copilot for Word into spreading hidden prompt injections from document to document.
Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence.
The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuine