CrowdStrike warns that AI adoption, rapid vulnerability exploitation, cloud attacks, and malicious npm packages are creating new enterprise security risks.
DHS Wants Protesters’ Signal Group Chats
A lawsuit accuses Homeland Security of violating protesters’ free-speech rights—but the agency is using it to try to get access to the plaintiffs’…
WhatsApp account takeover scam asks you to “vote for my friend”
Scammers are trying to take over WhatsApp accounts by sending messages asking people to vote for a friend in a fake online contest.
Anthropic models hack three firms, Coldcard bug drains $88 million, Midnight Blizzard hijacks hotel Wi-Fi
Claude Escapes the Lab, EU AI Act Enforced, SVR Hotel Wi‑Fi Hijacks, and $88M Bitcoin Wallet Flaw David Shipley covers multiple cybersecurity headlines:…
A week in security (July 27 – August 2)
A list of topics we covered in the week of July 27 to August 2 of 2026
OpenAI’s GPT-5.6 Tests Show Prompt-Injection Gains and Agent Risks
OpenAI’s latest GPT-5.6 safety results show low failure rates for direct prompt injection but higher success rates when attacks arrive through tools and…
Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks
Over time, passkeys are supposed to replace passwords. But what happens when malware steals the master key?
Focus on infrastructure resilience, not AI hype, Western government leaders warn
U.S. and allied officials said companies should start preparing now for a cyberattack that changes how they provide essential services.
The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
Security researcher James Kettle tried to push the limit of AI’s hacking abilities—and discovered how effective it can be when combined with human…
How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
The chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications.
Three AI security disclosures, fourteen days: what the warnings signs are telling us
This week, the UK’s AI Security Institute (AISI) published an incident report most organizations would have quietly buried. During a routine cyber…
Apple Challenges UK Demand For Access To Encrypted iCloud Data
Apple is challenging a UK order reportedly requiring access to encrypted iCloud data, reviving a wider dispute over privacy, security, and lawful access.
AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems
AISI found AI agents taking unsanctioned online actions, including social engineering and code attacks, during controlled cyber tests. The UK’s AI…
Apple briefly removes Telegram from App Store over reported CSAM violation
Apple briefly removed Telegram from the App Store over reported CSAM, highlighting moderation failures and the distribution power held by app-store…
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January…
Apple Seeks Injunction as OpenAI Blames Tech Giant for Security Lapses
Apple seeks an injunction against OpenAI as the companies clash over former employees, confidential hardware files, and internal security controls.
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a…
WhatsApp Users Say They’re Being Locked Out of Accounts by Mistake
Several WhatsApp users say they were wrongly suspended after automated moderation errors, raising concerns about appeals, access, and false positives.
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range…
OnePlus Nord 6 Gets Six Years of Security Updates, Four Android Upgrades
The OnePlus Nord 6 will receive six years of security updates but only four generations of Android upgrades. Here’s how that split could affect app…
Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives…
Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report.
Securing Branch Networks With Firewalls, VPNs, IDS/IPS, and Identity-Based Access
Branch networks no longer behave like quiet extensions of a single headquarters LAN. They terminate local user traffic, break out directly to the internet…
DHS Is Hiring Bounty Hunters to Find and Photograph Deported People’s Homes Abroad
Homeland Security told immigrants that leaving the US would wipe out fines it claims they owe. Now it wants private investigators to find them in their…