SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. “All of the malicious RubyGems packages appear to be typosquats of popular Ruby dependencies, but rather than the clever SEO-fueled typosquats we’ve seen from other threat actors (e.g., events-channel imitating the popular Node.js events module), they’re all clumsy typos.” The 16 gems have been published… OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker . The implant is equipped to harvest Windows credentials using pixel-perfect fake lock screens, offer a reverse SOCKS5 pivot into victim networks, execute arbitrary commands, and establish persistence on the host. There is no evidence that the technique has spread successfully in the wild, and the same paper reports that a review of archived posts from Moltbook, the social network for AI agents, found no successful agent-to-agent propagation despite several attempts.
The research highlights how compromised routers and IoT devices can be turned into distributed reconnaissance infrastructure that evades traditional IP-based defenses and supports follow-on exploitation. The botnet uses these devices to conduct targeted scanning and fingerprinting, helping threat actors rapidly identify vulnerable infrastructure—sometimes within hours of a new vulnerability disclosure—and appears to have a particular focus on U.S. military-related networks. This abuse has caused people to believe that fake images and videos are genuine and dismiss real content as misinformation.
More alerts are making your team slower, and an outcome-based SOC fixes that July 20, 2026 Google’s $10,000 refund test shows why AI agents need zero trust August 18, 2026 Microsoft’s August 2026 Patch Tuesday fixes roughly 400 flaws, including three Zero-days, with one actively exploited and two publicly disclosed. NIST seeks input on modernizing the National Vulnerability Database as AI reshapes vulnerability management, risk assessment and remediation. As enterprises race to bolt AI onto every business process, security leaders are being forced to answer a harder question… The program could allow vetted private US companies to access targeted systems without the owner’s authorization and, in more disruptive operations, damage or destroy systems or infrastructure.
Sogang University data breach exposes information of 180,000 people
- Both versions were released last month.
- The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent coding collaboration and in a chain of paired agents modeled on OpenClaw , the open-source autonomous assistant formerly known as Clawdbot and Moltbot .
- Given the urgency, analysts and consultants want to hear more about what to do when agents go rogue, as well as how to better control all agent actions.
- The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.
- NIST seeks input on modernizing the National Vulnerability Database as AI reshapes vulnerability management, risk assessment and remediation.
Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. In a statement shared with TechCrunch, the iPhone maker said it alerted an unspecified number of users targeted in 110 countries and that it has notified customers in over 150 countries to date. Apple on Thursday sent a fresh batch of notifications to customers whom it suspects may have been targeted by mercenary spyware attacks. The ransomware payload ultimately failed to deploy due to insufficient virtual memory. Trump expands private-sector role in U.S. offensive cyber operations, raising governance concerns.
Shadow hVNC Gives Attackers Remote Desktop Control Without Moving the Victim’s Mouse
President Trump’s bold vision to secure and accelerate American artificial intelligence (AI) innovation is being actioned through the creation of “GOLD EAGLE,” a clearinghouse that enables unprecedented cybersecurity vulnerability coordination. The report also found that cyberattacks are already a recurring business risk. Both versions were released last month. Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Windows ticketing keeps private-key operations available while the user is interactively signed in, allowing code running as the user to ask Windows to sign authentication data.
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent coding collaboration and in a chain of paired agents modeled on OpenClaw , the open-source autonomous assistant formerly known as Clawdbot and Moltbot . Security researchers at Anthropic and Switzerland’s EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. Global malware activity climbed sharply over the past week,… A fast-moving campaign is turning a VMware vCenter flaw into a route to full control of virtual infrastructure. Shadow hVNC is a remote access tool built to operate where victims cannot see it. C2Looper is a newly identified backdoor that gives attackers a quiet way to control a compromised Windows computer.
- “Salesforce took this action because our security teams recently detected unusual activity involving the app that may have resulted in unauthorized access to a subset of customer data via the app’s connection to Salesforce,” it noted .
- Mandy Lamb, Head of Value-Added Services at Visa Europe, contends that Visa’s new platform will help financial institutions identify cyber risks earlier…
- Hackers deploy AI agents to breach Taiwanese government systems.
- This abuse has caused people to believe that fake images and videos are genuine and dismiss real content as misinformation.
- Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.
- If teams can suddenly create many times more code, security can also end up with many more components, dependencies, findings, and fixes to manage.
- CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145 , which is a subgroup within Sandworm (aka APT44, Seashell Blizzard, and UAC-0002), a sophisticated hacking group affiliated with the GRU.
- Shadow hVNC is a remote access tool built to operate where victims cannot see it.
- “Some of GitHub’s internal repositories contain information from customers, for example, excerpts of support interactions. If any impact is discov…
- The company said it detected and responded to the incident targeting its production infrastructure earlier last week.
- Google’s Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9.
“Specifically, on job search websites, after reviewing a candidate’s resume, the attackers contact a potential victim – typically a system administrator or IT specialist – on behalf of an IT company https://lifestyll.net/what-are-exciting-hobbies-for-tech-enthusiasts/ (such as ATLAS Business Group),” CERT-UA said . The campaign is assessed to be ongoing since May 2026. CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145 , which is a subgroup within Sandworm (aka APT44, Seashell Blizzard, and UAC-0002), a sophisticated hacking group affiliated with the GRU. This week has plenty of them, covering cloud services, AI tools, malware, data breaches, scams, and new attack methods.
The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The Justice Department has never named the company, in Wednesday’s announcement or in the October 2024 indictment, identifying the victim only as a U.S. software-as-a-service (SaaS) pr… The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people.
Shell Investigates Data Breach After Cl0p Ransomware Claims Theft of 89GB Corporate Data
They also discuss OpenAI’s Trusted Access for Cyber program and what it takes to give security practitioners access to powerful AI capabilities while managing the risks of misuse. Breaking cybersecurity news, news analysis, commentary, and other content from around the world. Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America. The trust framework underlying Belgium’s electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.
Targets of the campaign include manufacturing, automotive, aerospace, and retail sectors. Several Artifactory https://e-beginner.net/category/cybersecurity-fundamentals/ CVE records were published on July 27 with affected-version ranges and fixed-version thresholds, but neither JFrog nor OpenAI has said whether any of those records correspond to the vulnerabilities used during the evaluati… OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face’s production environment also hacked multiple third-party accounts and services as part of the attack. Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without its knowledge.
Fact Sheet: President Donald J. Trump Promotes Advanced Artificial Intelligence Innovation and Security
Adform is telling people to clear their browser cache because the altered file may remain cached after the fix, and to check any wallet address before sending funds. Attackers modified a JavaScript file served by advertising technology company Adform , turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. “We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques,” the company said. N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. A configuration that allowed arbitrary devices on that APN to communicate with one another let the attacker pivot from a compromised wind-farm network to a controller at the CHP plant. While the intruders were still active inside the network, and customers lost neither heat nor electricity.
