- Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectableby info@thehackernews.com (The Hacker News) on August 3, 2026
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before […]
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incompleteby info@thehackernews.com (The Hacker News) on August 3, 2026
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those […]
- Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Codeby info@thehackernews.com (The Hacker News) on August 3, 2026
Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute […]
- OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problemsby Mayank Parmar on August 2, 2026
OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in […]
- COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theftby Lawrence Abrams on August 2, 2026
A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds […]
- Google Chrome may soon block New Tab hijacker extensions by defaultby Mayank Parmar on August 2, 2026
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search […]
- Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutesby info@thehackernews.com (The Hacker News) on August 1, 2026
An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the […]
- Rails patches critical Active Storage flaw with RCE potentialby Bill Toulas on August 1, 2026
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and […]
- Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sitesby info@thehackernews.com (The Hacker News) on August 1, 2026
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet […]
- Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interactionby info@thehackernews.com (The Hacker News) on August 1, 2026
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation […]
- Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malwareby info@thehackernews.com (The Hacker News) on August 1, 2026
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, […]
- Amgen says cloud data breach exposed patient health, proprietary infoby Lawrence Abrams on July 31, 2026
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems […]
- Arch Linux disables AUR package adoption to stop malware floodby Bill Toulas on July 31, 2026
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. [...]
- Online ad firm Adform’s script compromised to steal cryptocurrencyby Bill Toulas on July 31, 2026
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing […]
- OpenAI says its new GPT 5.6 models are becoming more cost-efficientby Mayank Parmar on July 31, 2026
OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient. […]
- Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurkby info@thehackernews.com (The Hacker News) on July 31, 2026
A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, […]
- Hacker uses DeepSeek AI to autonomously attack vulnerable serversby Lawrence Abrams on July 31, 2026
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with […]
- CISA warns of cyberattacks disrupting U.S. water utilitiesby Bill Toulas on July 31, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic […]
- HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firmby info@thehackernews.com (The Hacker News) on July 31, 2026
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as […]
- Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacksby Steve Alder on July 31, 2026
Health sector organizations have been warned about an increase in successful attacks by the ShinyHunters threat group. In contrast to The post Health-ISAC […]
- Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxiesby info@thehackernews.com (The Hacker News) on July 31, 2026
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then […]
- This month in security with Tony Anscombe – July 2026 editionon July 31, 2026
OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat made for a packed July roundup
- ESET tracks rise in malicious AI skills and adaptable malwareby Sponsored by ESET on July 31, 2026
Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of […]
- Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combinedby info@thehackernews.com (The Hacker News) on July 31, 2026
Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company […]
- Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flawby info@thehackernews.com (The Hacker News) on July 31, 2026
An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could […]
- 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026by info@thehackernews.com (The Hacker News) on July 31, 2026
Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an […]
- Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacksby info@thehackernews.com (The Hacker News) on July 31, 2026
Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. […]
- Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizationsby info@thehackernews.com (The Hacker News) on July 31, 2026
Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an […]
- Anthropic's Claude breached 3 orgs, uploaded PyPI malware during testsby Ax Sharma on July 31, 2026
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems […]
- South Korea fines telco giant KT $39 million for customer data breachby Bill Toulas on July 30, 2026
South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data […]
- JetBrains warns of critical TeamCity remote code execution flawby Bill Toulas on July 30, 2026
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. […]
- DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malwareby info@thehackernews.com (The Hacker News) on July 30, 2026
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages […]
- Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackersby Bill Toulas on July 30, 2026
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. [...]
- Read This Before You Buy That TV Streaming Stickby BrianKrebs on July 30, 2026
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, […]
- ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Storiesby info@thehackernews.com (The Hacker News) on July 30, 2026
A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a […]
- Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Databaseby info@thehackernews.com (The Hacker News) on July 30, 2026
A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to […]
- Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documentsby info@thehackernews.com (The Hacker News) on July 30, 2026
Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. […]
- The Network Has Become the Control Plane for AI Securityby info@thehackernews.com (The Hacker News) on July 30, 2026
Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and […]
- Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Promptsby info@thehackernews.com (The Hacker News) on July 30, 2026
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those […]
- SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRATby info@thehackernews.com (The Hacker News) on July 30, 2026
The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a […]
- Beyond the screenshot: Why you should verify what you seeon July 30, 2026
The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuine
- Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotationby info@thehackernews.com (The Hacker News) on July 30, 2026
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, […]
- FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risksby info@thehackernews.com (The Hacker News) on July 30, 2026
The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move […]
- Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleetby info@thehackernews.com (The Hacker News) on July 30, 2026
Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto […]
- Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Databy info@thehackernews.com (The Hacker News) on July 30, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management […]
- Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploadsby info@thehackernews.com (The Hacker News) on July 29, 2026
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application […]
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memoryby info@thehackernews.com (The Hacker News) on July 29, 2026
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, […]
- Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escapeby info@thehackernews.com (The Hacker News) on July 29, 2026
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been […]
- Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offlineby info@thehackernews.com (The Hacker News) on July 29, 2026
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide […]
- Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Paymentsby info@thehackernews.com (The Hacker News) on July 29, 2026
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an […]































