Key takeaways AI agents create a new email attack surface because they can process content before humans see it Email Agent Hijacking hides instructions in email content to manipulate AI interpretation, decisions, or outputs Post-delivery controls are too late when…
AI Agents are Only As Effective as Their Harness
Every AI vendor is talking about agents – autonomous systems that handle complex tasks without constant human input. The promise is real. But one question gets asked too rarely: what makes an agent reliable enough to trust with your network security? The…
Lumen expands managed detection and response with Cortex XSIAM integration
Lumen Technologies has announced Lumen Defender Advanced Managed Detection and Response (AMDR) for Palo Alto Networks Cortex XSIAM. Attackers are increasingly operating earlier in the lifecycle while AI is accelerating threat speed. This expanded service will bring together Lumen’s managed…
Cloudflare Precursor uses continuous behavioral analysis to stop advanced bots
Cloudflare has announced the general availability of Precursor, a next-generation, continuous behavioral validation engine for bot management. Precursor runs seamlessly inside web browsers to monitor entire user sessions in order to detect bot automation. Unlike static CAPTCHAs, it analyzes ongoing…
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts. Distributed via Telegram and costing $400 a…
New compliance guidance available: HITRUST i1 on AWS
We are pleased to announce the publication of a new AWS compliance implementation guidance: HITRUST i1 Compliance on AWS: Customer Implementation Guidance with an Illustrative Healthcare Platform. Healthcare organizations seeking HITRUST i1 certification increasingly rely on Amazon Web Services (AWS)…
EU Targets FSB-Linked Hackers in New Sanctions Over Cyber Sabotage
EU sanctions target nine people and four entities tied to Russia’s FSB over a 15-year cyberespionage and critical infrastructure sabotage campaign. The European Union imposed sanctions on Monday targeting nine individuals and four entities linked to a Russian cyberespionage and…
Novel OAuth Client ID Spoofing Technique Targets Cloud Environments
New research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments This article has been indexed from www.infosecurity-magazine.com Read the original article: Novel OAuth Client ID Spoofing Technique Targets Cloud Environments
APT-C-60 Uses Proton Drive for SpyGlace
The APT-C-60 threat actor has continued targeting Japanese organizations with a spear-phishing campaign that abuses Proton Drive, Windows shortcut files, trusted developer platforms, and native Windows utilities to deliver the SpyGlace malware. This article has been indexed from CyberMaterial Read…
AssuranceAmerica Breach Exposes 7M Licenses
U.S. This article has been indexed from CyberMaterial Read the original article: AssuranceAmerica Breach Exposes 7M Licenses
Debian 13.6 Rolls Out Vital Security Fixes
The Debian Project has officially rolled out Debian 13.6, marking the sixth stable point update for the “trixie” distribution family. This article has been indexed from CyberMaterial Read the original article: Debian 13.6 Rolls Out Vital Security Fixes
EU and UK sanction Russian GRU cyber hackers
The European Union and the United Kingdom have launched a coordinated wave of sanctions against dozens of Russian individuals and entities accused of executing state-directed cyber and hybrid warfare across Europe. This article has been indexed from CyberMaterial Read the…
ESET H1 2026 Report and Major Data Breaches
The ESET H1 2026 threat report reveals that cybercriminals are rapidly evolving existing attack frameworks by integrating AI-flavored lures, enhanced social engineering, and advanced defense evasion techniques. This article has been indexed from CyberMaterial Read the original article: ESET H1…
IT Security News Hourly Summary 2026-07-13 15h : 10 posts
10 posts were published in the last hour 12:33 : Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens 12:32 : iPhone and MacBook Forensics Investigation Exposes £113,000 Property Fraud Operation 12:32 : Cybersecurity M&A Roundup:…
Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens
Internet-wide reconnaissance is expanding beyond conventional application targets to include Model Context Protocol (MCP) services, AI assistant configuration files, and locally exposed LLM endpoints. A 14-day review of Apache and ModSecurity logs from a small, low-traffic shared host found roughly…
iPhone and MacBook Forensics Investigation Exposes £113,000 Property Fraud Operation
A digital forensics investigation from Belkasoft into an iPhone and a damaged MacBook has helped secure the conviction of Jason Cunningham, a rent-to-rent property operator who defrauded landlords and investors of more than £113,000 through forged contracts and false promises.…
Cybersecurity M&A Roundup: 37 Deals Announced in June 2026
Significant cybersecurity M&A deals announced by 1Password, Accenture, Cisco, F5, Rubrik, and SailPoint. The post Cybersecurity M&A Roundup: 37 Deals Announced in June 2026 appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: Cybersecurity…
Fake OAuth client IDs are helping attackers slip past sign-in logs
Attackers running account enumeration against Microsoft cloud tenants have added a step that keeps their probing out of the usual telemetry. They spoof the OAuth client ID, the globally unique identifier assigned to an application and passed as client_id in…
Ransomware negotiator who betrayed clients sentenced to 70 months in prison
A former ransomware negotiator at incident response firm DigitalMint has been sentenced to 70 months in prison after admitting he shared confidential client information with the BlackCat ransomware group and later helped carry out ransomware attacks. Prosecutors say Angelo Martino,…
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory
Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration. “The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory…
Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots
A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a…
Meta Files Patent for AI That Can Listen All Day and Track How You’re Feeling
Meta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound, and keeps a timestamped log of every read. Each read…
Progress Software Warns of “External Security Threat” to ShareFile
Progress Software, the provider of the popular file-sharing and data storage solutions, has urged customers to shut down the server hosting their Storage Zone Controller This article has been indexed from www.infosecurity-magazine.com Read the original article: Progress Software Warns of…
World Cup grudge attackers may have scored Argentine FA access via year-old infostealer infection
Footie fans? Overreacting? There’s a first time for everything This article has been indexed from www.theregister.com – Articles Read the original article: World Cup grudge attackers may have scored Argentine FA access via year-old infostealer infection