Indian banks are ramping up cybersecurity spending as artificial intelligence-fueled cyber threats grow more sophisticated. As per the Digital Threat…
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been…
LogoKit Phishing Kit Screenshots Victim Sites in Real Time
LogoKit now builds per-victim phishing pages using live screenshots of the target’s real website
Critical SolarWinds Flaw Lets Attackers Bypass Web Help Desk SAML Login
SolarWinds has patched a critical security vulnerability in its Web Help Desk platform that could allow attackers to bypass SAML-based authentication.…
Anthropic and OpenAI are competing to see whose agents can go rogue harder
Whoever wins, we lose
MCBS Healthcare Data Breach Affects 1.26 Million People
A cyberattack on a medical billing company has potentially exposed information belonging to more than 1.26 million people, underscoring that healthcare’s…
CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In
Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at…
Fitness Trackers Can Expose Your Health Data, EFF Warns
Fitness trackers have become part of everyday life, helping people monitor steps, sleep, heart rate, stress, and workouts with impressive convenience. But…
SSH Bot Profiles Linux CPU, GPU and RAM Before Deploying Cryptocurrency Miner
A new SSH bot has been caught quietly logging into Linux systems, profiling their CPU, GPU, and memory, and then walking away without dropping any visible…
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI…
DeepSeek-Powered Hermes Agent Launches Autonomous Cyberattacks Against Exposed Servers
A Chinese-speaking threat actor used an AI-driven agent to search for vulnerable internet-facing servers and begin attacks with little direct human input.…
Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging
ShutterGap Exposes Millions of AWS Resources Between Cloud Security Scans
Cloud security teams often utilize Cloud Security Posture Management (CSPM) and Cloud-Native Application Protection Platform (CNAPP) tools to identify…
Ernst & Young Notifies Clients Following Third-Party Support Platform Data Breach
The company Ernst & Young (EY) has sent out notices to the affected clients about the data breach involving the third-party support ticket platform, which…
CMMC Phase II Is Paused, But Contractors’ Data-Security Obligations Are Not
By John Grancarich, EVP, Head of Defense & Intelligence, Fortra The recent pause affecting the implementation of Cybersecurity Maturity Model…
Cyber Briefing: 2026.07.29
Active zero-day exploitation, massive consumer-facing scams, and recurring enterprise breaches highlight severe operational and financial vulnerabilities…
Enterprise ERP AI Adoption Outpaces Security Readiness
A new Onapsis report finds AI adoption across ERP systems is outpacing security readiness.
As data breaches grow costlier, ungoverned AI creates new risks
Meanwhile, many companies still aren’t doing the basics to protect on-premises data, IBM found.
Critical Flaw Allowed to Azure Cosmos DB Pwnage
Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access.
Secure your npm and pip package updates in Amazon Linux
If you use and install packages from npm or PyPI, the first hours after a package is published are the riskiest because scanners can’t analyze packages…
FBI And Allies Warn of North Korean IT Workers Using Stolen Identities
The U.S. State Department, FBI, and allied governments including Japan, Canada, Germany, Australia, the United Kingdom, and the Republic of Korea have…
Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide…
AI robocalls: Why caller ID is still lying to you
AI is making robocall scams cheaper, more convincing, and harder to spot. Here’s why caller ID still isn’t enough.
Google AI Supercharges Chrome Security, Fixing 1,072 Bugs
Google says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google’s…