Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched.
Vanta Stealer Uses PyArmor to Steal Browser Passwords, Crypto Wallets and Discord Tokens
Vanta Stealer is a Python‑based, cross‑platform information stealer that uses layered PyArmor obfuscation on top of a PyInstaller‑packed executable to…
Critical Jenkins Vulnerability Allows Attackers to Execute Malicious Code on Controller
Jenkins has disclosed a critical security vulnerability that could allow attackers to execute malicious code on a Jenkins controller by bypassing a…
Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses
Cybersecurity researchers have disclosed a security issue with Apple’s iCloud Private Relay tool that can expose a user’s real IP address. Introduced with…
OWASP Releases GenAI LLM Top 10 2026 for Building and Securing Modern AI Apps
The Open Web Application Security Project (OWASP) has officially released the Top 10 for LLM Applications 2026, a foundational security guide targeting…
Three in four AI-generated vulnerability patches leave something broken
Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write.…
Remus Hides Its Command Server on Ethereum While Emptying Browser Vaults
Remus is a newly active information‑stealing malware that quietly slips into Windows systems, locks onto popular web browsers, and drains their saved…
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains. Introduced in the…
Public PoC Released for Linux Kernel Bridge Use-After-Free Vulnerability
A public proof-of-concept has been released for a use-after-free flaw affecting the Linux kernel’s bridge subsystem, specifically its Spanning Tree…
Amazon and Apple impersonated in “$149.99 unauthorized charge” scam
Different logos, different color schemes, same scam.
Discounted Claude access bought on the gray market may expose every prompt you send
More than half a dozen services advertised on underground forums and messaging platforms, offering discounted or “unlimited” token access to frontier AI…
Critical Paperclip Flaw Allowed Admin Access, Code Execution
An attacker could self-register, sign in for board-level API access, and import a new company for code execution.
IT department put sticky notes on the laptops to help employees log in
Leaving this information exposed allowed someone else to gain access
Critical Jenkins Deserialization Flaw Allows Attackers to Execute Code on Controllers
A critical vulnerability in Jenkins, tracked as CVE-2026-70426, may allow attackers to execute arbitrary code on Jenkins controllers by bypassing…
OpenAI Agents Discover Zero-Day and Leave the Door Open for Other Models
OpenAI has revealed at the Black Hat security conference that AI agents involved in a cybersecurity evaluation found previously unknown vulnerabilities…
Kill switch fears now rival ransomware as a top security risk for European businesses, Proton study finds
For years, the security team’s job has been to defend against cyberattacks. New research from Proton suggests that job now needs to extend to a very…
Adversarial Clothing Designed to Fool Facial Recognition Systems
There are many companies manufacturing adversarial clothing designed to confuse facial recognition systems. It’s a cool idea, but I worry that it’s mostly…
16-31 July 2026 Cyber Attacks Timeline
103 confirmed cyber incidents reported between 15 and 31 July 2026 — including attacker motivations, top techniques, initial access vectors, hardest-hit…
Anthropic’s Mythos AI used social engineering to target real people
Testers found that Anthropic’s AI agent Mythos attempted to social engineer Github developers into accepting malicious code.
KHunt Toolkit Turns Oracle SQL Injection Into SYSTEM-Level RCE and Credential Theft
KHunt shows how a “routine” SQL injection against an Oracle‑backed web app can be weaponized into SYSTEM‑level remote code execution and credential theft…
Meta AI Model Gained Internet Access and Hacked Another Organization’s Network
Meta has disclosed that one of its AI models gained unintended access to the internet during a cybersecurity evaluation and then exploited a vulnerability…
16-31 July 2026 Cyber Attacks Timeline Infographic
103 confirmed cyber incidents reported between 15 and 31 July 2026 — including attacker motivations, top techniques, initial access vectors, hardest-hit…
Meta Confirms AI Model Launched Autonomous Attack on Another Organization
Meta has become the latest technology company to disclose that an AI agent accessed another organization’s online systems during a controlled…
Canadian Hacker Pleads Guilty Over Snowflake Extortion Campaign
A Canadian hacker has admitted involvement in the widespread compromise of 165 Snowflake customer accounts used to steal data and extort victims