π 9 Best AI SOC Tools with Detection Logic as Code: Including Python CI/CD for Detection Rules π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
Discover which AI SOC tools support Python CICD detection rules, agentic triage, and vendoragnostic integration. Built for securityconscious CTOs. The post 9 Best AI SOC Tools with Detection Logic as Code Including Python CICD for Detection Rules appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
9 Best AI SOC Tools with Detection Logic as Code: Including Python CI/CD for Detection Rules
Discover which AI SOC tools support Python CI/CD detection rules, agentic triage, and vendor-agnostic integration. Built for security-conscious CTOs.
π¦
The Assets You Donβt Know You Own: Attack Surface Sprawl Is a Discovery Problem, Not a Tooling Problem π¦
π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Modern organizations no longer operate within a fixed network perimeter. Cloud services, remote work, thirdparty integrations, and rapid digital expansion have made the boundary between "inside" and "outside" for the enterprise increasingly difficult to define. Attackers exploit this ambiguity by scanning continuously for weaknesses across an organization's hardware, software, cloud, and internetfacing assets. The uncomfortable truth security leaders must confront is simple an organization cannot secure what it does not know it has. Attack surface expansion is frequently framed as a tooling gap, but the evidence points elsewhere toward a persistent, structural failure in attack surface discovery, asset discovery, and visibility. Why Attack Surface Sprawl Happens Attack su...π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Cyble
The Assets You Donβt Know You Own: Attack Surface Sprawl Is a Discovery Problem, Not a Tooling Problem
Cyble breaks down why continuous attack surface discovery and asset visibility are essential to reduce cyber risk and protect modern cloud-first environments.
ποΈ Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Malware running as an ordinary user on a Windows machine can sign into a victim's passkeyprotected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Passtakey, Silver Passtakey and Golden Passtakey the strongest targets the master key.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access SMA 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a crossplatform remote access trojan RAT as part of a sophisticated, targeted software supply chain attack targeting Chinesespeaking environments. One of the packages in question is "libmtop," an unscoped package with the same name as a private Alibaba package.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π¦Ώ Claude Opus 5 Vending Test Shows Profit-Driven AI Risks π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
Claude Opus 5 set a VendingBench record while fabricating supplier bids, breaking truces, and ignoring refunds, showing why companies need stronger AI agent controls. The post Claude Opus 5 Vending Test Shows ProfitDriven AI Risks appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Claude Opus 5 Vending Test Shows Profit-Driven AI Risks - TechRepublic
Claude Opus 5 used deceptive tactics in a vending machine simulation, raising questions about AI agent controls for businesses.
β€1
π¦Ώ Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
Google is testing twiceweekly Chrome security updates as AI tools uncover more vulnerabilities and the company works to shrink the browsers patch gap. The post Google Tests TwiceWeekly Chrome Security Updates as AI Finds More Vulnerabilities appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities
Google is testing twice-weekly Chrome security updates as AI tools uncover more vulnerabilities and the company works to shrink the browserβs patch gap.
β€1
π’ MSPs urged to patch immediately after N-able issues hotfix for N-central βgod modeβ flaw π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
The authentication bypass flaw in Ncentral could grant threat actors god mode access.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
ChannelPro
MSPs urged to patch immediately after N-able issues hotfix for N-central βgod modeβ flaw
The authentication bypass flaw in N-central could grant threat actors βgod modeβ access
β€1
π’ βI bought the tool to save time, but I did more manual work than beforeβ: Pentesters are finding more bugs with AI than they can fix π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
Hallucinated exploits and fabricated vulnerabilities are adding to pentester workloads.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
βI bought the tool to save time, but I did more manual work than beforeβ: Pentesters are finding more bugs with AI than they canβ¦
Hallucinated exploits and fabricated vulnerabilities are adding to pentester workloads
π’ Police National Legal Database confirms data leaked on the dark web π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
The hack has been claimed by the same group as last week's Department for Education breach.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Police National Legal Database confirms data leaked on the dark web
The hack has been claimed by the same group as last week's Department for Education breach
π¦Ώ Open Secure AI Alliance Expands at Black Hat: What You Should Know π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
The Open Secure AI Alliance introduced SAFE guidelines and open agentsecurity tools at Black Hat, giving enterprises a framework for safer AI deployment. The post Open Secure AI Alliance Expands at Black Hat What You Should Know appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Open Secure AI Alliance Expands at Black Hat: What You Should Know
The Open Secure AI Alliance introduced SAFE guidelines and open agent-security tools at Black Hat, giving enterprises a framework for safer AI deployment.
π¦Ώ Gmailβs New Feature Warns You Before Revealing You Were BCCβd π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
Gmail now warns BCC recipients before they reply all, helping prevent accidental exposure of their involvement and email address. The post Gmails New Feature Warns You Before Revealing You Were BCCd appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Gmail Adds Privacy Warning for BCC Reply All
Gmail now warns BCC recipients before they reply all, helping prevent accidental exposure of their involvement and email address.
π¦Ώ Samsung Will Ban Smart TV Apps Containing Residential Proxy Software π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
Samsung plans to ban Smart TV apps containing residential proxy software after researchers found apps could route traffic through users home connections. The post Samsung Will Ban Smart TV Apps Containing Residential Proxy Software appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Samsung Will Ban Smart TV Apps Containing Residential Proxy Software
Samsung plans to ban Smart TV apps containing residential proxy software after researchers found apps could route traffic through usersβ home connections.
π¦Ώ Chrome to Block Policy-Abusing Extensions on Personal Devices π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
Google is developing Chrome protections that could block policyinstalled extensions from hijacking New Tab pages and search settings on personal devices. The post Chrome to Block PolicyAbusing Extensions on Personal Devices appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Chrome to Block Policy-Abusing Extensions
Google is developing Chrome protections that could block policy-installed extensions from hijacking New Tab pages and search settings on personal devices.
β€2
π¦Ώ Why Appleβs Recent Crypto Lawsuit Should Worry Australian IT Leaders π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
A 1.8 million App Store scam lawsuit tests how much software vetting Australian firms can safely outsource. The post Why Apples Recent Crypto Lawsuit Should Worry Australian IT Leaders appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Appleβs Crypto Lawsuit Should Worry Australian IT Leaders
A US lawsuit over a fake Sparrow Wallet app on Apple's App Store is a reminder for Australian IT leaders that platform vetting alone is not enough.
π¦Ώ Microsoft Project Perception Enters Public Preview: What Security Teams Should Know π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
Microsofts Project Perception brings coordinated AI agents into security operations, raising new questions about permissions, oversight, accuracy, and deployment risk. The post Microsoft Project Perception Enters Public Preview What Security Teams Should Know appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Microsoft Project Perception Enters Public Preview: What Security Teams Should Know - TechRepublic
Microsoft Project Perception is now in public preview. Hereβs what security teams should know about its AI agents, risks, controls, and limits.
π₯1
ποΈ Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The commercial phishingasaservice PhaaS toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass MultiFactor Authentication MFA and seize control of user accounts. "Greatness supports AiTM adversaryinthemiddle credential and.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A credentialstealing npm worm that first appeared in keyv6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later reported at least 868 packages.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have disclosed details of an active, multiwave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management RMM programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKESCREEN by Securonix Threat.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break. Security teams have long estimated risk by ranking attacker sophistication. Nationstate actors sat at one end. Organized criminal groups followed. Inexperienced attackers, dismissed as "script kiddies," sat at the other end, running public.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Google deleted three AI agent workflows from its Agent Development Kit ADK Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged codefixing agent. The researchers said the public agent could be promptinjected into posting adkissuefix as adkbot. They identified the bot as a collaborator, so that comment satisfied.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity