An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil's Health Surveillance Informa
New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. ThreatLabz identified victims of a campaign a
NatJack attack class exposes design flaw across decades of network infrastructure. At Black Hat USA 2026, researcher Malcolm Stagg, an independent researcher and Synack Red Team member, disclosed NatJack, an attack class that manipulates the NAT connection tracking table. An atta
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability, tracked as CVE-2026-7406. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. Thi
Three WebKit mechanisms have been discovered to bypass Apple's iCloud Private Relay. In fact, the mechanisms can bypass any browser‑level proxy configuration, including Psylo's proxy, Tor-on-iOS proxy setups, and so on. Private Relay is a VPN-like system for Safari on iOS which i
Zbtlink routers phone home, waiting for orders. Not because they were hacked. Because they were shipped that way. These routers are made by Zbtlink, a brand of Shenzhen Zhibotong Electronics, a Chinese manufacturer that builds routers and white-labels them for sale globally. The
A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. 26-year-old Connor Riley Moucka, also known as Alexander Mou
The UK's data protection regulator has criticized London's Metropolitan Police Service (MPS) after its officers handed a victim's stalker details about her new phone number and home address, among other failures. The Information Commissioner's Office (ICO) today issued the MPS wi
In the keyv/cacheable compromise that has been unfolding since yesterday, it is the one thing you should not do first -- because revoking the stolen token is exactly what arms the payload. On August 4, 2026, an attacker took over the maintainer account behind the widely used keyv
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. Infected packages include very popular ones such as Keyv and Cacheable, flat-cache and file-entry-cache, all
'The UK’s AI Security Institute (AISI) has put something uncomfortable on the table: during cyber testing, frontier models didn’t just follow instructions badly. In some runs, they crossed into real-world actions, touched real people and organisations, and then tried to make the
A significant data breach has hit SplitVPN, a Russian VPN provider formerly known as NotVPN, exposing the personal records of roughly 865,000 unique users. The incident, which occurred in July 2026, has raised fresh concerns about the reliability of "no-logs" promises made by pri
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. BleepingComputer spotted the protection in a chain of work-in-progress Chromium Gerrit changes. It has not shipped
Researchers suspect that a vulnerability in COLDCARD hardware wallet firmware was exploited to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. Digital asset research firm Galaxy Research says
CVE-2026-10848: Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg). The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied th
I began tracking a subset of what was assessed to be low level criminal activity, which actually turned out to be a group of six officers working together within the PRC People's Liberation Army (PLA) Troop 61786. This group appears to be associated with Advanced Persistent Threa
Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact. The actor, op
Our story comes courtesy of Kevin Walker, a seasoned IT veteran from the UK. At one point, he was providing his services to a school when he came across the headteacher's (aka principal's) laptop. At the bottom of the laptop there was a sticker with the woman's username and passw
Western frontier AI is not sold in mainland China. It is used there every day. This report maps the infrastructure that makes that possible, and counts it for the first time: 73K internet-facing servers, tracked continuously by Infrawatch, reselling access to the models the Weste
Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The IGSS product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a de
A critical vulnerability chain in Azure Cosmos DB enabled full read and write access to every Cosmos DB database. Wiz Research uncovered CosmosEscape, a critical vulnerability in Azure's flagship database service, Azure Cosmos DB, via its Gremlin API. The vulnerability could have
CVE-2026-68563 describes an information disclosure vulnerability in `ansible-collection-redhat-leapp` related to insecure backup permissions for PostgreSQL data. A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and
Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller. The following versions of Watchfire Controller Software are affected: BC550 12.30, BC750 11.33|12.35, BC76
Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application are affected: Core Flight System (cFS) Health & Safety (HS) Application <=v7.0
Numbat is Perplexity's open-source agent security suite for client endpoints. It detects, prevents, and investigates risky AI agent behavior on macOS, Linux, and Windows. Recent advances in agent autonomy give rise to security incidents that need not assume the existence of adver
The average cost of a data breach has risen to almost $5m, analysis of the consequences of cyber incidents which took place during the last year has revealed. The figure was published in the 2026 edition of the annual IBM Cost of a Data Breach Report, released on July 29, and bas
CVE-2026-15157 has been identified, where `undici` does not validate the `type` property of a duck-typed blob-like request body before using it as the `Content-Type` header on the HTTP/1.1 dispatcher. In `undici` before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to
CVE-2026-14643: undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives. This vulnerability was published on July 29, 2026, at 10:16 p.m. undici's cache interceptor mishandles optional whitespace placed around the equals sig
Guangdong Chanming. If you were looking for them, you'd be disappointed. No public website, no storefront, and certainly no obvious product line to speak of. On the surface, they are a ghost. But for those of us that know how to look for the cracks in the Great Firewall, the brea
Twenty years ago, a British mathematician named Clive Humby popularized a phrase that came to describe data's relationship with the entire global economy: "Data is the new oil." Pithy as the phrase sounds, it is undeniably true. Data steers decisions at businesses of every size.
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack. Ernst & Young disclosed the breach earlier this month, saying a third-party s
MedusaHVNC RAT uses hidden Windows desktops to remotely control browsers, steal data, and evade detection through legitimate system features. BlackFog's research team recently dissected this new remote access trojan. According to the report published by Blackfog, "We recently cam
GitHub has introduced a default three-day cooldown period for Dependabot version updates to reduce the risk of projects automatically adopting new malicious packages. This change targets a prevalent pattern in software supply chain attacks where attackers compromise a trusted pac
Earlier this month, the European Union sanctioned the Russian hosting provider Media Land and associated individuals and companies, following US criminal charges that the company knowingly operated a 'bulletproof hosting' service for ransomware groups including LockBit, BlackSuit
Confused Deputy" flaws persist in Google Cloud and Microsoft Azure, a category of vulnerabilities that allows an attacker to easily acquire administrative level permissions and bypass cloud providers' access controls. Significant cracks in the managed identity trust chains of the
Spring Boot exposes the endpoint "/actuator/heapdump" to collect debug information. By default, the endpoint will return a file heapdump.hprof, which includes a binary heapdump that can be used to analyze the current state of the application. Non-Java readers may be familiar with
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. This flaw, identified as CVE-2026-17497, allows for arbitrary OS command execution via Tauri shell:allow-
A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026,
CVE-2026-10681 details an SMP race in `thread_idx_alloc()` that lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot. This vulnerability occurs within Zephyr's userspace dynamic-objects subsystem. Specifically, `thread_idx_alloc()` in kerne
Hunt.io uncovered a cyber-espionage attack on Thailand's Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence. Researchers at Hunt.io have uncovered an intrusion targeting Thailand's Ministry of Finance that offers a rare look inside a live
Google has started rolling out a new way to recover access to your account if you've lost your phone or forgotten your password: a "selfie video" verification option. In practice, it introduces new security and privacy questions, raises concerns about deepfakes, and creates anoth
A widespread DNS poisoning campaign is targeting hotels, conference venues, and the hospitality sector with credential harvesting attacks designed to steal corporate login credentials from visitors, researchers have warned. Identified by cybersecurity analysts at ReliaQuest, the
Click To Pray, a prayer app endorsed by the Pope with hundreds of thousands of users worldwide, has leaked people's names and email addresses for months - or longer - according to an ethical hacker who said she found and reported the security vulnerability six months ago to no av
Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway. Victims are asked to log in with their email address and password to claim free Call of Duty Points (CP), the game's premium currency. Following this, they're th
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so
The Russia-aligned threat actor TA458, the group behind Operation RoundPress, continues to focus on webmail targeting using half-click exploits as a way to steal highly sensitive email data. TA458 is likely aligned with Russia's General Staff Main Intelligence Directorate (GRU).
Australian energy provider Origin Energy has confirmed a data breach by an unknown threat actor that exposed customers' personally identifiable information (PII). Origin Energy is Australia's largest energy retailer, providing electricity, natural gas, and broadband internet serv
Proofpoint uncovered that Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) was exploiting a previously unknown vulnerability against Zimbra mailservers for at least five months during 2025, until the issue was patched with CVE-2025-66376. After successful exploitat
Long a laggard in RPKI adoption, China has dramatically increased its ROA coverage from 4% to 81% since April, signaling a major commitment to securing the internet's routing system. This marks a significant milestone in global routing security, helping to protect networks from B
A car alarm vendor's coding mistake has left millions of vehicles vulnerable to theft and location tracking. The device is the KARR Security System, a Bluetooth-enabled aftermarket alarm built by Acrisure Protection Group. It's installed by dealers, primarily at Honda, Toyota, Ma