495 scanned. Nothing on fire. Read at your own pace.
Data source: supabase
Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store.
Your workforce is building agents in Salesforce Agentforce, Microsoft Copilot Studio, Cursor, Zapier, Retool, and a dozen other tools, often without visibility or approval from IT or security.
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers.
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory.
ChatGPT is experiencing a major outage, and users are unable to load chats, including previous conversations. The outage started at approximately 5 AM ET and is affecting users worldwide, including those in the US and Europe.
Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services
American fast food restaurant chain Chick-fil-A has confirmed that over 13,000 customers had their data stolen in a recent wave of credential stuffing attacks.
An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos, which he later traded or sold online.
Australian energy provider Origin Energy has confirmed a data breach by an unknown threat actor that exposed customers' personally identifiable information (PII). The company has 4.
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware.
I spent years on the offensive side of security performing red and purple team assessments, bypassing controls that GRC teams, and often times even auditors, were convinced were working.
Jul 23, 2026 ICS Advisory | ICSA-26-204-03 Weintek cMT3092X
Jul 23, 2026 ICS Advisory | ICSA-26-204-04 Panduit IntraVUE
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
Microsoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers' mailboxes since Sunday.
Cloud storage costs tend to creep up over time, since most services charge monthly or annually for as long as you use them.
American fast food restaurant chain Chick-fil-A is notifying an undisclosed number of customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks.
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.
Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia.
Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
Jul 21, 2026 ICS Advisory | ICSA-26-202-01 Tycon Systems TPDIN-Monitor-WEB2
The U.S. Justice Department has seized more than 1,000 websites and blocked 1,970 domains used to stream FIFA World Cup 2026 matches without authorization.
Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out.
The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol.
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system.
Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week.
Microsoft has released emergency updates to fix a known issue causing some Dell PCs to experience performance issues or shut down after installing the July 2026 Windows 11 security updates.
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies.
Age checks are becoming law worldwide. The question is no longer whether platforms verify age, but what happens to the faces they collect -- and whether they need to collect them at all.
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes.
Residential proxies are no longer treated as a simple anonymity tool in carding circles.
U.S. prosecutors on Thursday charged a New York man and woman for their roles in a large-scale crime ring that laundered money stolen in cyber investment fraud scams.
A flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude's access to co
A new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data.
For most of the last two decades, enterprise security ran on a workable assumption: the environment was knowable.
Two leading members of the Scattered Spider cybercrime collective were sentenced to five years and six months in prison each for hacking Transport for London (TfL) in 2024.
Rockwell Automation FactoryTalk DataMosaix
Jul 16, 2026 ICS Advisory | ICSA-26-197-08 Rockwell Automation Flex 5000 Adapter
Microsoft announced on Wednesday that systems running Windows 10 Enterprise LTSB 2016 and Home and Pro editions of Windows 11 24H2 will stop receiving updates in three months.
A financially motivated Russian threat actor tracked as UAT-11795 is using trojanized software to steal credentials and cryptocurrency by deploying a new backdoor called Starland RAT.
Stakeholder-Specific Vulnerability Categorization (SSVC)
Microsoft is blocking this month's Windows 11 security updates on some Dell devices because they are causing shutdowns and performance issues.
Microsoft has released Windows 11 KB5101650 and KB5099414 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features.
Microsoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026.
Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA).
Jul 14, 2026 ICS Advisory | ICSA-26-195-01 ABB Advant Master Online Builder
Jul 14, 2026 ICS Advisory | ICSA-26-195-02 ABB Ability Edgenius
Microsoft is now testing a cleaner and faster version of Windows Search that should prioritize relevant results over ads and promotional content.
The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public GitHub repository for almost six months before being notified
German discount supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands that attackers stole their personal information in a breach at a service provider.
UK authorities charged five people following a National Crime Agency (NCA) investigation into Russian Coms, a major caller ID spoofing platform used by criminals to make over 1.8 million scam calls.
Defending Against China-Nexus Covert Networks of Compromised Devices
The European Union and the United Kingdom jointly sanctioned dozens of Russian individuals and entities and accused Russia of coordinating a network of hacking groups responsible for attacks across Europe.
OpenAI is temporarily relaxing GPT-5.6 Sol usage limits after demand for the company's most powerful model surged over the past 48 hours.
Anthropic has just extended access to Claude Fable 5 for paid subscribers until July 19, giving you another week to keep using the most powerful model.
A new version of the RedHook Android malware abuses the Android Wireless Debugging (Wireless ADB) mechanism in a novel way to gain shell-level privileges without requiring a computer connection.
The Dutch National Police (Politie) says it has found "strong indications" that Dutch hackers have been involved in a February breach at the telecommunications provider Odido.
The OpenMandriva Linux project announced that it was the target of an attempted act of internal sabotage after a dispute among contributors.
Hackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phr
A new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to steal data from SharePoint environment
A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation.
Schneider Electric PowerChute Serial Shutdown
Jul 09, 2026 ICS Advisory | ICSA-26-190-01 OpenPLC v3
American insurance company AssuranceAmerica has disclosed a data breach impacting nearly 7 million drivers after attackers gained access to its systems earlier this year.
Mount Royal University in Calgary says hackers stole and then deleted data from its file storage systems after breaching the university's network.
Malicious packages on the Node Package Manager (npm) and the Python Package Index (PyPI) delivered stealer malware to developers and users of Paysafe, Skrill, and Neteller payment applications.
A threat actor has been targeting organizations across multiple sectors with voice-based fake security requests that ask Microsoft 365 users to enroll a new Entra passkey.
IBM’s 2025 Cost of a Data Breach Report found that 16% of breaches studied involved attackers using AI tools, most often for phishing or deepfake impersonation attacks.
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based
Organizations continue to invest in secure email gateways, multi-factor authentication, and identity protection, yet phishing, business email compromise (BEC), and account takeover (ATO) attacks remain a
Jul 07, 2026 ICS Advisory | ICSA-26-188-03 Hitachi Energy e-mesh EMS
Jul 07, 2026 ICS Advisory | ICSA-26-188-04 Siemens Mendix Studio Pro
Microsoft says the Windows settings backup and restore tool will be enabled by default on Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems after upgrading to Windows 11 26H2.
Microsoft has begun testing the Cloud Rebuild recovery feature in the latest Windows 11 Insider Preview builds released for users in the Experimental channel.
A phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals.
Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks.
Vietnamese authorities have arrested and are prosecuting seven suspects believed to have run HiAnime, the largest anime piracy streaming service before its shutdown in June.
Author: Morey J. Haber, Chief Security Advisor, BeyondTrust Every major evolution in software development has reduced the friction between an idea and a deployable solution.
Flipper Devices says development of the Flipper Zero firmware will continue, albeit with a smaller internal team and greater reliance on community contributions.
A new phishing-as-a-service (PhaaS) platform dubbed "ARToken" appears to operate as an affiliate of the EvilTokens phishing platform, giving researchers a glimpse into an extensive toolkit designed to compromise Mic
Anthropic says Claude Fable 5 won't be accessible via Claude subscriptions after July 7, but it's not a permanent change, and the company expects the model to return outside the usage-based plan soon.
Claude Fable, the company's most powerful model, is now available to all users, but early impressions are disappointing, as it appears to be nowhere near the original release.
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut , a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR].
Microsoft has fixed a known issue causing the Copilot Chat or Copilot buttons in Classic Outlook to disappear for Windows users with the Copilot Chat (Basic) license.
Jul 02, 2026 ICS Advisory | ICSA-26-183-03 Gardyn IoT Hub
Jul 02, 2026 ICS Advisory | ICSA-26-183-02 CubeSpace CW0057 Reaction Wheel
Opera has introduced Paste Protect, a security feature designed to block ClickFix-style attacks that trick users into executing malicious commands through social engineering.
Healthcare device firm Medtronic is notifying affected customers about a data breach that exposed their personal data to an unauthorized third party.
Microsoft has fixed the GIF functionality in the Emoji Panel for Windows 11 users after the provider shut down its service.
The U.S. Federal Trade Commission (FTC) says Amazon will pay a $2.25 million civil penalty to settle charges that it blocked identity theft victims' access to transaction records.
Anthropic has confirmed that the Department of Commerce has lifted export controls on Claude's two most powerful models, Fable 5 and Mythos 5.
Anthropic is now rolling out Sonnet 5, and it's almost as good as the Opus range, but it is designed to be cheaper than the company's flagship model.
A new prompt injection attack dubbed “BioShocking” could trick AI-powered browsers into treating real-world risky actions as part of a fictional scenario, causing them to ignore any safety guardrails.
Microsoft announced today that it is accelerating its quantum-safe security roadmap, saying advances in quantum computing are bringing the need to replace today's encryption standards sooner than previously expected.
A malicious extension in the Chrome Web Store is masquerading as the Perplexity AI answer engine, intercepting search traffic and collecting browsing information.
Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M
Jun 25, 2026 ICS Medical Advisory | ICSMA-26-176-01 pydicom pynetdicom Library
Jun 30, 2026 ICS Advisory | ICSA-26-181-02 Frangoteam FUXA SCADA/HMI
Kali Linux 2026.2, the second release of the year, is now available for download, featuring 9 new tools and numerous Kali NetHunter improvements.
OpenAI confirms ChatGPT is down worldwide
Microsoft blames massive Microsoft 365 outage on maintenance bug
Chick-fil-A data breach affects more than 13,000 customers
Man gets six years for hacking 750 women's Snapchat accounts
Australian energy provider Origin says data breach exposes client data
Fake Claude app promoted by Bing ads pushes SectopRAT malware
Microsoft working to fix Exchange Online mailbox quarantine issue
Stop renting storage space — this lifetime 2TB plan is yours for $59
Chick-fil-A discloses data breach after credential stuffing attacks
Inside the Search for "Clean" Residential Proxies for Carding
Claude Chrome extension flaw lets malicious extensions trigger AI actions
Microsoft starts testing cleaner Windows Search without ads
Microsoft to enable Windows settings backup by default for orgs
Microsoft testing new Cloud Rebuild Windows 11 recovery feature
Fake IT support calls on Microsoft Teams push EtherRAT malware
Microsoft fixes bug that removed Copilot buttons in Outlook
Microsoft fixes GIF functionality in the Windows Emoji Panel
Anthropic to restore Claude Fable access on Wednesday