Protective DNS is the rare control where the cheap options are genuinely good so this comparison leads with value. The verdict: DNSFilter is the best…
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can…
The Best Firewall Management Tools, Compared and Priced (2026)
The firewall policy management market had its earthquake: Skybox Security shut down overnight in February 2025, selling its technology to Tufin and…
Hackers Hid a Remote-Control Toolkit Inside Oracle to Take Over a Windows Server
A routine web application weakness has been tied to a serious Windows Server compromise after attackers used SQL injection to plant a remote-control…
Cyber Briefing: 2026.08.06
Cyber adversaries are actively exploiting critical software vulnerabilities and leveraging shared infrastructure to execute unauthorized breaches, launder…
Algorithmic Pricing Raises Transparency and Consumer Fairness Concerns
Artificial intelligence (AI) algorithms are driving a new way of setting prices for goods and services that leave little room for consumer privacy or…
Apple WebKit vulnerabilities reveal your IP address, despite Private Relay
Researchers have found three methods to bypass Apple’s Private Relay which is supposed to shield users’ IP addresses and location.
Meta AI Agent Exploited Third-Party Flaw During Cybersecurity Test
Meta is investigating after an AI model hacked another company during testing, raising concerns over agent containment and enterprise security safeguards.
Novel-reading apps used users’ phones to generate fake ad traffic
A new mobile ad fraud scheme, dubbed Papyrus, is using a cluster of novel-reading apps to generate hidden browser traffic, according to IAS Threat Lab.…
Snowflake Hacker Pleads Guilty in US Court
Connor Riley Moucka was extradited to the United States in July 2025 after he was arrested in Canada.
TeamPCP Traced Back to 2020 Cryptojacking Operation
Oligo Security has linked TeamPCP to ShadowRay 2.0 and to cryptojacking infrastructure dating back to 2020
One Fake Movie Download Can Expose Passwords, Payments and Crypto Assets
Cybercriminals are weaponizing pirated downloads of the blockbuster theatrical release “The Odyssey (2026)” to deliver Lumma Stealer. This prolific…
CISA Warns of Exploited Langflow, N-central, Tomcat Flaws
The Cybersecurity and Infrastructure Security Agency has issued warnings about three vulnerabilities now under active exploitation in the wild.
OpenAI and Anthropic AI Agents Crossed Testing Boundaries During Cybersecurity Evaluations
A separate cybersecurity evaluation conducted by OpenAI and Anthropic revealed that artificial intelligence models were behaving in unexpected ways…
Black Hat 2026: Critical Flaws Found in Anthropic, Google, and OpenAI Coding Agents
Researchers disclosed critical flaws in AI coding agents from Anthropic, Google, and OpenAI that could enable credential theft, RCE, and supply chain…
Greatness PhaaS Uses Phishing Code to Escape 2FA and Attacks Microsoft 365 Users
The commercial phishing-as-a-service (PhaaS) toolkit called Greatness, distributed via Telegram that uses token theft with device code and…
Mac Malware Found Draining Crypto Wallets After Fake CAPTCHA Trick
Researchers at Huntress have uncovered a strain of macOS malware that can gradually siphon funds out of victims’ cryptocurrency wallets, after tracing an…
Black Hat USA: TP-Link Flaws Put Omada Controllers and Camera Feeds at Risk
Forescout disclosed 15 TP-Link flaws at Black Hat USA 2026 that could expose Omada credentials and VPN keys, allow internal access and affect VIGI camera…
Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident
One of Meta’s AI models exploited a third-party security flaw during an evaluation, the latest in a series of similar incidents involving advanced AI…
Shared C2 Kit Links State & Criminal Operators
Security researchers analyzing state-sponsored intrusion campaigns have documented a fundamental shift in how nation-state actors build their operational…
Photos: Black Hat USA 2026
Photo gallery from the Business Hall at Black Hat USA 2026. Interesting booths, demo stages, crowded aisles, and the moments in between. Featured vendors:…
Apple bug bounty flooded with AI-generated reports
Apple has introduced new submission restrictions on its bug bounty portal following a surge of AI-generated vulnerability reports that threatened to…
Critical Paperclip AI Agent Flaws Allow Unauthenticated Remote Code Execution
Critical vulnerabilities in the open-source Paperclip AI-agent orchestration platform could allow attackers to execute commands remotely on exposed…
Coldcard hackers launder $4.5M in BTC/ETH
Threat actors responsible for exploiting Coldcard hardware wallets have moved $4.5 million in stolen cryptocurrency through mixing protocols in an attempt…