ποΈ Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own codingagent repositories. On OpenAI's, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SDWAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SDWAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode. "These vulnerabilities were found.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π Healthcare and Victim Support Charities Affected by Beacon Cyber Incident π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Beacon has informed around 1500 customer charities that its CRM databases were accessed and likely exfiltrated by an unauthorized actor.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Healthcare and Victim Support Charities Affected by Beacon Cyber Incid
Beacon has informed around 1500 customer charities that its CRM databases were accessed and likely exfiltrated by an unauthorized actor
π CrowdStrike OverWatch vs. Dedicated AI SOC: When Endpoint-Layer MDR Is No Longer Enough π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
Compare CrowdStrike OverWatch vs a dedicated AI SOC and see when endpoint MDR stops covering identity and cloud. Evaluate your options today. The post CrowdStrike OverWatch vs. Dedicated AI SOC When EndpointLayer MDR Is No Longer Enough appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
CrowdStrike OverWatch vs Dedicated AI SOC: Endpoint Isn't Enough Anymore
Compare CrowdStrike OverWatch vs a dedicated AI SOC and see when endpoint MDR stops covering identity and cloud. Evaluate your options today.
π Google Links Redact Extortion Group to BlackFile Rebrand π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
BlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaigns.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Google Links Redact Extortion Group to BlackFile Rebrand
BlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaigns
π 10 Best AI SOC Platforms with Slack and Teams Verification: ChatOps Feature Comparison for SOC Buyers π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
Explore how ChatOps verification separates real AI SOC platforms from noisy alert forwarders. Built for CTOs and security operations leaders in 2026 The post 10 Best AI SOC Platforms with Slack and Teams Verification ChatOps Feature Comparison for SOC Buyers appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
10 Best AI SOC Platforms with Slack and Teams Verification: ChatOps Feature Comparison for SOC Buyers
Explore how ChatOps verification separates real AI SOC platforms from noisy alert forwarders. Built for CTOs and security operations leaders in 2026
π Ransomware Surges in July After Q2 Lull π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Finance, technology and healthcare sectors were particularly heavily targeted in July, according to Comparitech.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Ransomware Surges in July After Q2 Lull
Finance, technology and healthcare sectors were particularly heavily targeted in July, according to Comparitech
π¦
Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actors π¦
π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Europe faced a ransomware onslaught in the first half of 2026 that sets a troubling precedent for the remainder of the year. According to Cyble Research and Intelligence Labs CRIL, the region experienced 866 documented ransomware attacks, 51 confirmed data breach incidents, and 7 initial access sales between January and June 2026. These figures represent not just a volume problem, but a fundamental shift in how threat actors are organizing, targeting, and monetizing their operations within European territory. What distinguishes the ransomware threats in Europe from other global regions is the concentration of power among a small number of highly sophisticated threat actors. While the threat ecosystem encompasses dozens of groups, five dominant ransomware operators account for approx...π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Cyble
Ransomware Threats In Europe H1 2026: A Deep Dive
Ransomware threats in Europe have escalated in 2026. Know the patterns and dominant actors behind it through Cyble's Research and Intelligences Labs' findings.
π Toolkit Hidden Inside Oracle Database Evades Endpoint Tools π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Attackers used SQL injection to compile a postexploitation toolkit inside an Oracle database.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Toolkit Hidden Inside Oracle Database Evades Endpoint Tools
Attackers used SQL injection to compile a post-exploitation toolkit inside an Oracle database
π TeamPCP Traced Back to 2020 Cryptojacking Operation π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Oligo Security has linked TeamPCP to ShadowRay 2.0 and to cryptojacking infrastructure dating back to 2020.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
TeamPCP Traced Back to 2020 Cryptojacking Operation
Oligo linked TeamPCP to ShadowRay 2.0 and to cryptojacking infrastructure dating back to 2020
π Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
One of Metas AI models exploited a thirdparty security flaw during an evaluation, the latest in a series of similar incidents involving advanced AI systems.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident
One of Metaβs AI models exploited a third-party security flaw during an evaluation, the latest in a series of similar incidents involving advanced AI systems
π Violent Physical Crypto Thefts Surge to $30m in Losses π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Socalled wrench attacks have resulted in 30m in losses so far in 2026, says Chainalysis.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Violent Physical Crypto Thefts Surge to $30m in Losses
So-called βwrench attacksβ have resulted in $30m in losses so far in 2026, says Chainalysis
π Canadian Hacker Pleads Guilty Over Snowflake Extortion Campaign π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
A Canadian hacker has admitted involvement in the widespread compromise of 165 Snowflake customer accounts used to steal data and extort victims.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Canadian Hacker Pleads Guilty Over Snowflake Extortion Campaign
A Canadian hacker has admitted involvement in the widespread compromise of 165 Snowflake customer accounts used to steal data and extort victims
π NVIDIA Group Proposes SAFE Initiative for Agentic Threat Intel Sharing π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
The Open Secure AI Alliance has announced plans for the Shared AI Findings Exchange SAFE.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
NVIDIA Group Proposes SAFE Initiative for Agentic Threat Intel Sharing
The Open Secure AI Alliance has announced plans for the Shared AI Findings Exchange (SAFE)
ποΈ Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Attackercontrolled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signedin user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over thirdparty accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email. PortSwigger researcher Gareth.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Metabase has warned that a maximumseverity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zeroday. The vulnerability CVSS score 10.0, which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Nable has released a fresh round of hotfixes for Ncentral as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management RMM product. "We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," the company said. "This is not a duplicate of our.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The U.S. Cybersecurity and Infrastructure Security Agency CISA on Friday added a criticalseverity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities KEV catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE20268037 CVSS score 9.6, is a command injection flaw that could be weaponized to achieve arbitrary.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver crossplatform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typosquatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ClickFixstyle attacks are being used to deliver a Gobased malware capable of stealing cryptocurrency assets, as well as browserstored passwords, Apple iCloud Keychain data, and cached credentials. The macOSfocused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture. ".π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity