π AI SOC and Analyst Retention: Moving Senior Engineers Off Alert Triage and Onto Work Worth Keeping Them For π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
Is SOAR dead? Discover why playbooks stall on investigation and how an AI SOC reasons per alert to cut noise. The post AI SOC and Analyst Retention Moving Senior Engineers Off Alert Triage and Onto Work Worth Keeping Them For appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
Benefits of having an AI SOC over a SOAR
Is SOAR dead? Discover why playbooks stall on investigation and how an AI SOC reasons per alert to cut noise.
π Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
A Chinesespeaking threat actor has been using DeepSeeks AI models to orchestrate cyberattacks targeting Asian organizations.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
A Chinese-speaking threat actor has been using DeepSeekβs AI models to orchestrate cyber-attacks targeting Asian organizations
ποΈ Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browserside tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities. Anyone who visited a site carrying the affected script on July 27 and copied a Bitcoin,.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Adobe has released security updates to address a maximumseverity security flaw in Campaign Classic ACC, its enterprisefocused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE202648449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A fake browser update served over hijacked hotel WiFi has been used to deliver CornFlake, a remote access trojan RAT that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attribute it to Storm2945. It assesses Storm2945 to be an operational subcluster of Midnight Blizzard, also known as.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π This month in security with Tony Anscombe β July 2026 edition π
π Read more.
π Via "ESET - WeLiveSecurity"
----------
ποΈ Seen on @cibsecurity
OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AIdriven supply chain threat made for a packed July roundup.π Read more.
π Via "ESET - WeLiveSecurity"
----------
ποΈ Seen on @cibsecurity
Welivesecurity
This month in security with Tony Anscombe β July 2026 edition
OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat made for a packed July roundup.
ποΈ Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about 70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoinonly hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator PRNG.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
β€2
ποΈ N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Nable said attackers exploited an authentication bypass in Ncentral to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE202618577 affects Ncentral builds prior to 2026.3.1.7. Nable shipped build 2026.3.1.7 on August 2 as the first unaffected version. Ncentral is the remote monitoring and management platform.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Three highseverity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence AI supply chain to security risk. "These vulnerabilities are bypassing trustremotecode, the safeguard designed to stop unreviewed code from running in the.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor's July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented. Thermo Fisher tracks the issue as CVE202617583 and rates it.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π Coldcard Users Lose $89m After Bitcoin Wallet Is Hacked π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
A hacker has drained nearly 89m from Coldcard Bitcoin wallets after exploiting a legacy bug.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
β€2
π’ One-in-five breaches are now AI-related, IBM warns π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
While AI threats are rising, enterprises are bolstering cyber resilience capabilities.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
One-in-five breaches are now AI-related, IBM warns
While AI threats are rising, enterprises are bolstering cyber resilience capabilities
ποΈ β‘ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ FOMO in the SOC: Where AI Platforms like Claude Actually Fit ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
AI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. The conversation has evolved from whether AI belongs in the SOC, to where each type of AI delivers the most value. With so many new AI.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
An unknown Chinesethreat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services AWS signin pages on a domain that also hosts the exploit toolkit. ".π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The Police National Legal Database PNLD has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers. The incident, identified on July 26, also exposed some names.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Chinese actors exploited the critical React2Shell exploit inside a day, while 88 of exploited vulnerabilities in H1 2026 were compromised within 48 hours of disclosure.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
π Midnight Blizzard Targets Travelers via Captive Portals π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Russian actor Storm2945 hijacked hotel captive portals to push fake updates and steal tokens.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Midnight Blizzard Targets Travelers via Captive Portals
Russian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokens
π HollowFrame Loader Uses Fake Python DLL to Evade Defender π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
New HollowFrame loader hid Go code in a fake Python DLL after prestaging Defender exclusions.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
π Koreaβs Largest Telco KT Fined $38m After Femtocell Campaign π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Korean telco KT has been fined 39m for a yearlong breach linked to femtocell compromise.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
π 11 Best AI SOC for Manufacturing in 2026: Compared on IT and OT Coverage π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
Explore our practitionerbuilt comparison of AI SOC platforms for manufacturing, ranked on real OTICS coverage and response, not just IT triage. The post 11 Best AI SOC for Manufacturing in 2026 Compared on IT and OT Coverage appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
11 Best AI SOC for Manufacturing in 2026: Compared on IT and OT Coverage
Explore our practitioner-built comparison of AI SOC platforms for manufacturing, ranked on real OT/ICS coverage and response, not just IT triage.