Zenity Raises $125 Million in Series C Funding
The AI security company will invest in product innovation, global expansion, and customer experience. The post Zenity Raises $125 Million in Series C Funding appeared first on SecurityWeek.
Weaponized Email AI Assistants Could Help Attackers Hijack Accounts
Researchers demonstrate how attackers could abuse built-in email chatbots to evade detection, impersonate trusted employees, compromise executive accounts, and facilitate financial fraud. The post Weaponized Email AI Assistants Could Help Attackers Hijack Accounts appeared first on SecurityWeek.
CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout
Russ Kirby, CISO at Ping Identity, shares how passion, courage, and “good enough” thinking shaped his path from HP to the C-suite—and what keeps him up at night. The post CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout appeared first on SecurityWeek.
Oligo Raises $60 Million for Runtime Security
The company will use the investment to accelerate product innovation and expand go-to-market operations. The post Oligo Raises $60 Million for Runtime Security appeared first on SecurityWeek.
Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer
Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. The post Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer appeared first on SecurityWeek.
Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 2) appeared first on SecurityWeek.
Water Sector Cyberattacks Reportedly Hit at Least 12 States
Georgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption. The post Water Sector Cyberattacks Reportedly Hit at Least 12 States appeared first on SecurityWeek.
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek.
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass. The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek.
AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations
In one instance, an unsanctioned model attempted to inject malicious code into an open source repository. The post AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations appeared first on SecurityWeek.

One C2 kit. 30 customers. 2 governments
I was mapping the command-and-control infrastructure behind a state-linked intrusion set when the query came back and effectively ended the exercise I thought I was running. The malware resolved its C2 address by reading a smart contract on a public blockchain. Public reporting described one contract. Working from the chain rather than the sample, I […]

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The “evil twin” extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have […]

Your orchestration framework choice is a security decision, not just an engineering one
Comparisons of LangChain, CrewAI and AutoGen are easy to find — dozens of guides this year cover the same ground: developer experience, ecosystem maturity, how easy it is to wire up multi-agent workflows. None of them ask the question I actually care about: does the framework you pick change how easily your agent gets compromised? […]

Why you need a reliable AI agent kill switch
Recent high-profile rogue agent incidents involving OpenAI and Anthropic underscore the fact that organizations can’t put blind trust in their AI guardrails. Moreover, they must able to turn off agents quickly when they deviate from intended behavior — before they can do potentially catastrophic damage. For legal services company Purpose Legal, that includes incorporating a […]

Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
An agent running Anthropic’s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK’s AI Security Institute. When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch history to erase the evidence, […]

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows – CVE-2026-9198 (CVSS score: 9.8) – A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve […]

AI threat report: Rogue agents, workflow attacks
Malicious AI use and threats to AI systems are requiring cyber teams to double down on security fundamentals and rethink the future of their approaches to defense. Newly emerging AI-enabled attacks, proofs of concept, and in-the-wild techniques, as well as the latest AI vulnerability and risk research, present inklings not only about what enterprises presently […]
Risky Business #847 -- Oops! Claude's accidental hacking spree
On this week’s show Patrick Gray, and James Wilson are joined by bearded man of leisure Adam Boileau to discuss the week’s cybersecurity news, including: Accidental AI agent hacking sprees have the world’s media freaking out, but we think it’s all pretty funny The bugpocalypse is so chaotic, Microsoft can’t patch fast enough A ColdCard […]

QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application […]
ISC Stormcast For Wednesday, August 5th, 2026 https://isc.sans.edu/podcastdetail/10038, (Wed, Aug 5th)
Post Content

Ruby on Rails critical bug puts every image upload under scrutiny
A new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, CVE-2026-66066, could turn a seemingly innocuous image into a front door to your secrets. Disclosed July 30, the high severity CVE (scored 9.5 out of 10) poses a significant risk to enterprises running apps that handle user-uploaded images in Rails. Dubbed “KindaRails2Shell,” […]

ChainDrop credential stealing worm infects over 400 npm packages
A self-propagating worm-like attack is hitting the npm registry, having infected 444 packages from more than a dozen publishers so far. The impact is massive, with the packages affected amounting to more than 2 billion monthly downloads combined. The attack began with the compromise of a GitHub account belonging to Jared Wray, who maintains Keyv, […]
23-01170(2).pdf
23-01170(2).pdf Anonymous (not verified) Tue, 08/04/2026 – 17:10 Case ID 23-01170 Forum FINRA Document Type Motion to Vacate Claimants Wells Fargo Clearing Services, LLC Respondents Wade Roberts Neutrals George Pinckney Shingler Hearing Site Atlanta, GA Award Document 23-01170(2).pdf Documentum DocID c3828692 Award Date Official Thu, 09/26/2024 – 12:00 Related Content On Claimant Representatives Keith J. […]
25-02217.pdf
25-02217.pdf Anonymous (not verified) Tue, 08/04/2026 – 17:00 Case ID 25-02217 Forum FINRA Document Type Award Claimants Scott Seltzer Respondents J.P. Morgan Securities, LLC Neutrals Lise Gabrielle Hunter Joseph V. Simeri Dineo Coleman Gary Hearing Site Boca Raton, FL Award Document 25-02217.pdf Documentum DocID 7c8700e6 Award Date Official Mon, 08/03/2026 – 12:00 Related Content Off […]
VIRTU AMERICAS LLC
VIRTU AMERICAS LLC fnrw-backend Tue, 08/04/2026 – 15:40 MC ID KCGM MC Reporter Type Alternative Trading System MC Paragraph MC Link https://www.virtu.com/about/transparency/rule-605-and-606-reporting/ MC Last Updated Tue, 08/04/2026 – 15:39
VIRTU AMERICAS LLC
VIRTU AMERICAS LLC fnrw-backend Tue, 08/04/2026 – 15:39 MC ID ITGP MC Reporter Type Alternative Trading System MC Paragraph MC Link https://www.virtu.com/about/transparency/rule-605-and-606-reporting/ MC Last Updated Tue, 08/04/2026 – 15:39
VIRTU AMERICAS LLC
VIRTU AMERICAS LLC fnrw-backend Tue, 08/04/2026 – 15:37 MC ID NITQ MC Reporter Type Single Dealer Trading System MC Paragraph MC Link https://www.virtu.com/about/transparency/rule-605-and-606-reporting/ MC Last Updated Tue, 08/04/2026 – 15:37
The AI assurance gap: CIOs need proof that agentic AI controls actually work
Enterprises have spent decades learning how to audit people and software. Agentic AI creates a third category: systems that interpret instructions, call tools and act across workflows without a mature assurance model built around them. In my work as a leader and investor across technology-enabled businesses, I have spent years around automation, cybersecurity, compliance, workflow […]
Don’t let your company be fooled by AI efficiency
The scenario isn’t hypothetical: Some of the companies that went furthest in replacing people with AI have had to backtrack. For example, in 2024 Klarna became a European benchmark for what AI could do for a company. Its AI assistant handled two-thirds of customer service chats in its first month, performing the equivalent of 700 full-time agents. As […]
Why AI infrastructure needs a new operating model
The next AI infrastructure crisis may come from unmanaged inference capacity. For the past several years, the AI infrastructure conversation centered on one question: how do we get more compute? That made sense. Enterprises needed GPUs, cloud capacity, foundation models and room to experiment. Compute became shorthand for AI readiness. Production AI changes the operating […]
20 traits of innovative and invaluable project managers
Projects are becoming more complex, with higher stakes and faster delivery times. At the same time automation and AI are changing how projects are designed, managed, and delivered. Indeed, some pieces of project management are now routinely handled by machines. Some may think that AI and automation will make project managers obsolete, or at least […]
The enterprise AI strategy that outlasts any single model
In January of this year, few enterprise tech leaders would have bet on Anthropic over OpenAI. Today, Claude reigns supreme (inspiring a notable 180 by Elon Musk), with Gemini threatening to take market share and introduce pricing models that could flip the leaderboard on its head again. That’s exactly why betting on a single model […]
Why meta agents must become the economic intelligence layer of the agentic enterprise
In “Micro and macro agents: The emerging architecture of the agentic enterprise,” I proposed a three-layer architecture for enterprise AI. Micro agents execute specialized tasks. Macro agents orchestrate end-to-end business processes. Meta agents provide governance through monitoring, compliance, security, and human oversight. As enterprises begin deploying thousands — and eventually tens of thousands — of […]
AI agents get better at IT ops, but only with humans in the loop
AI agents are performing roughly 1 in 3 actions in enterprise IT workflows (but that share is rising quickly), while human analysts are rejecting about one-quarter of AI-proposed actions (but that rate is falling), according to a new study of tens of thousands of human-AI interactions. Operational data, rather than underlying AI infrastructures, is often […]

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. “Greatness supports AiTM [adversary-in-the-middle] credential and

Airlock Digital Unveils Agentic AI Control & Governance to Extend Preventative Endpoint Security
Airlock Digital, a leader in preventative endpoint security, today announced Agentic AI Control & Governance at Black Hat USA 2026. The new capabilities build on application control by providing command- and session-level visibility into trusted AI agent behavior, centralized policy management for trusted applications and AI agents, and real-time governance over what trusted AI agents […]
Sage Water Resources says Utah saltwater disposal controller intrusion bypassed pump safeguards
Dysruption reports on a critical infrastructure attack in Utah that could have caused more damage than some other recent attacks: Sage Water Resources said workers stopped malicious changes to an automated controller at its oilfield wastewater disposal site near Duchesne, Utah, before the March 15 intrusion caused equipment failure or environmental damage. In an Aug…. […]
Florida Man Sentenced for Conspiracy to Commit Wire Fraud
Stolen wallets are still a thing. From the U.S. Attorney’s Office, Eastern District of Kentucky: July 31, 2026 LEXINGTON, Ky. – An Orlando, Fl., man, Ivory Joe Pruitt, 61, was sentenced on Friday to 63 months imprisonment by U.S. District Judge Robert Wier for conspiracy to commit wire fraud. Pruitt was also ordered to pay $137,392.74… […]

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later […]

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKE#SCREEN by Securonix Threat
Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)
This morning, I noticed specific sources “hunting” for vulnerabilities in URLs that I haven’t noticed before. All of these URLs appear to be associated with diagnostic tools:
Republican attorneys general urge OpenAI to preserve records on Hugging Face breach
Miranda Nazzaro reports: More than a dozen Republican attorneys general are calling on OpenAI to preserve records on its models’ recent breach of another company, suggesting the AI firm may have violated state or federal laws in the incident. In a letter sent Monday to OpenAI CEO Sam Altman, 15 attorneys general wrote the ChatGPT-maker may have… […]
Swiss federal IT office hit by cyberattack
SwissInfo.ch reports: Following a cyberattack on the SharePoint servers operated by the Federal Office of Information Technology, Systems and Telecommunication (FOITT), access via the internet has been blocked for people outside the federal administration. Around 200 accounts were compromised in the incident. There are no indications of any further data breaches. The unknown attackers are… […]

Critical Azure Cosmos DB flaw threatened cross-tenant database takeover
A critical vulnerability in Microsoft Azure’s Cosmos DB database service could have enabled attackers to escape the platform’s Gremlin query sandbox, execute code on shared infrastructure, and ultimately gain access to any customer’s database, including data stores used by Microsoft services such as Entra ID, Teams, and Copilot, according to research published by cloud security […]

The top new cybersecurity products at Black Hat USA 2026
Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products. Vendors are increasingly packaging AI into operational workflows, while pairing automation with governance, exposure management, and recovery capabilities aimed at making autonomous security more practical for enterprise environments. […]
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability These types of vulnerabilities are a frequent attack […]
Acrisure KARR BT and DR-100
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations. The following versions of Acrisure KARR BT and DR-100 are affected: KARR BT firmware <July_20_2026 DR-100 firmware <July_20_2026 CVSS Vendor Equipment Vulnerabilities v3 8.1 Acrisure Acrisure KARR BT and DR-100 Use of Hard-coded Cryptographic Key Background Critical […]
Thermo Fisher Applied Biosystems Genetic Analyzers
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results. The following versions of Thermo Fisher Applied Biosystems Genetic Analyzers are affected: Applied Biosystems 3500/3500xL Series Data Collection Software <=4.0.2 Applied Biosystems 3730/3730xL Series Data Collection Software <=5.0.2 […]

Google ADK flaws reveal what happens when AI agents trust the wrong message
Security flaws in automated workflows in the GitHub repository for Google’s Agent Development Kit for Python could allow public-facing AI agents to trigger more privileged automation, opening one path to manipulate pull-request reviews and another to expose credentials, according to a report from Pillar Security. The first attack path involved a triage agent that analyzed […]

When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted
The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break. Security teams have long estimated risk by ranking attacker sophistication. Nation-state actors sat at one end. Organized criminal groups followed. Inexperienced attackers, dismissed as “script kiddies,” sat at the other end, running public

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent. The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so […]
Horizon3 Raises $250 Million to Fund Continuing Growth
Venture financing has become an essential factor in growing new business in today’s fast moving economy. Horizon3’s latest funding explains how and why. The post Horizon3 Raises $250 Million to Fund Continuing Growth appeared first on SecurityWeek.
River Bank Says Hackers Deleted Data Stolen in Ransomware Attack
The bank holding company was hacked in June, but the investigation into the incident continues. The post River Bank Says Hackers Deleted Data Stolen in Ransomware Attack appeared first on SecurityWeek.
Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations
The list of people behind companies, foundations and trusteeships is part of efforts to combat money laundering and terror financing. The post Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations appeared first on SecurityWeek.
Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion
The payments giant says BioCatch’s behavioral and device intelligence will help financial institutions combat account takeovers, scams and other forms of digital fraud. The post Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion appeared first on SecurityWeek.
Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 1) appeared first on SecurityWeek.
New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems
The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure. The post New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems appeared first on SecurityWeek.
Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers
The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000. The post Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers appeared first on SecurityWeek.
150,000 Impacted by Madera Community Hospital Data Breach
An extortion group stole personal, financial, and medical information from the hospital’s network. The post 150,000 Impacted by Madera Community Hospital Data Breach appeared first on SecurityWeek.
Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login. The post Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks appeared first on SecurityWeek.
Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering
A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent. The post Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering appeared first on SecurityWeek.

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database’s root context, crossing the privilege boundary between a cPanel account and the server’s administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The database bug is tracked as CVE-2026-58048 (CVSS […]

Secure AI adoption starts with API best practices
You don’t need to be a fortune teller to understand where enterprise IT is headed. McKinsey reported in November that 62% of global organizations were experimenting, piloting or scaling agentic AI projects. More recently, Gartner forecast that worldwide spending on AI will top $2.59 trillion in 2026 – an increase of 47% from last year. […]

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims’ browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. “The first stage drops a steganographic PNG image into the browser’s cache, retrieves its hidden content, and executes […]

The Minnesota attackers may hold a better backup of your plant than you do
More than 30 Minnesota community water systems were hit by coordinated cyber activity against their operational technology on July 26 and 27; several lost remote control or deliberately cut it while operators contained the intrusion. The reporting since — including CSO’s own news analysis — has rightly chased two open questions: Who did it, and […]

Attackers are crafting malicious AI instruction files to turn your agentic workflows into quiet criminal helpers
AI agents are increasingly being deployed across the enterprise, a rapid adoption that has significantly broadened the organization’s attack surface, turning sharable AI agent resources and configuration files into backdoors, security experts warn. AI-assisted software developers have been increasingly targeted through malicious IDE extensions, rogue MCP servers, and poisoned AI skills, all of which provide […]

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows
ISC Stormcast For Tuesday, August 4th, 2026 https://isc.sans.edu/podcastdetail/10036, (Tue, Aug 4th)
Post Content
EQUITABLE ADVISORS, LLC
EQUITABLE ADVISORS, LLC fnrw-backend Mon, 08/03/2026 – 18:12 MC ID EQHA MC Reporter Type Broker-Dealer MC Paragraph MC Link https://www.lpl.com/disclosures/sec-605-equitable-disclosures.html MC Last Updated Mon, 08/03/2026 – 18:12
TRADE-PMR INC.
TRADE-PMR INC. fnrw-backend Mon, 08/03/2026 – 17:29 MC ID TPMR MC Reporter Type Broker-Dealer MC Paragraph MC Link https://www.tradepmr.com/order-routing-disclosures MC Last Updated Mon, 08/03/2026 – 17:29
2021069426901 UBS Financial Services Inc. CRD 8174 AWC vrp.pdf
2021069426901 UBS Financial Services Inc. CRD 8174 AWC vrp.pdf Anonymous (not verified) Mon, 08/03/2026 – 17:15 Case ID 2021069426901 Document Number 00747591 Document Type AWCs (Letters of Acceptance, Waiver, and Consent) Action Date Fri, 07/31/2026 – 12:00 Related Content Off Attachment 2021069426901 UBS Financial Services Inc. CRD 8174 AWC vrp.pdf
26-00488.pdf
26-00488.pdf Anonymous (not verified) Mon, 08/03/2026 – 17:10 Case ID 26-00488 Forum FINRA Document Type Award Claimants Michael Renshaw Respondents Robinhood Securities, LLC Neutrals Chandler R. Bridges Hearing Site Atlanta, GA Award Document 26-00488.pdf Documentum DocID 5c5483ca Award Date Official Mon, 08/03/2026 – 12:00 Related Content Off Claimant Representatives Michael J. Renshaw Respondent Representatives Michael […]
26-00144.pdf
26-00144.pdf Anonymous (not verified) Mon, 08/03/2026 – 17:10 Case ID 26-00144 Forum FINRA Document Type Award Claimants Paula Gomoll Respondents Charles Schwab & Co., Inc. Cetera Financial Specialists LLC Eric Wurtel Neutrals Mark W Solock Hearing Site Chicago, IL Award Document 26-00144.pdf Documentum DocID 14dab4c2 Award Date Official Mon, 08/03/2026 – 12:00 Related Content Off […]
AI can do your tasks. That doesn’t mean it will do your job
Much of the conversation around AI and work has centered on a single question: Will AI take my job? It’s an understandable concern. Every week AI becomes increasingly more capable. We see AI summarizing meetings, generating content, analyzing data, writing software and automating workflows that once required significant human effort. Agentic AI is also becoming […]
12 business analyst certifications to level up your career
Business analysts help organizations make the most of the data they collect by finding trends, patterns, and errors that might otherwise go unnoticed. Successful business analysts have the skills to work with data, the acumen to understand the business side of the organization, and the ability to communicate that information to people outside of IT. […]
Frontier AI will not break finance. Slow cyber decisions will
The scariest thing about frontier AI is that it gives lazy criminals better legs. That sounds flippant until you watch how cyber failure works. I have seen that weakness in many costumes: A server waiting for a patch, an access path nobody wants to touch, a supplier marked “low risk” because the contract said so, […]
CIOs risk being sidelined in enterprise AI initiatives
The AI revolution has created new opportunities for CIOs, with expanded responsibilities and more authority, but some observers see the opposite happening at some organizations. While many CIOs have become the main executive leading AI strategy and initiatives, some organizations have set the responsibility for AI deployment and adoption with another executive. That puts CIOs […]
The missing role in every enterprise AI strategy: The analytics engineer
Every enterprise AI strategy these days has mostly the same core cast: Software engineers who log online events data, data engineers who move data from online to offline data warehouses, data scientists who build machine learning models, AI/ML engineers who deploy these models to production systems and data analysts who consume these data outputs and […]
AI’s measurement crisis is over. The translation crisis is next
Last fall, you couldn’t open a business publication without tripping over some version of the same headline: where is the ROI for AI? The anchor for most of that coverage was MIT’s “GenAI Divide” report, which found that despite $30 to 40 billion in enterprise generative AI spending, 95% of pilots delivered no measurable P&L […]
Companies winning with AI operate differently. Here’s how.
The first phase of the AI race was largely about access. Companies rushed to adopt tools, launch pilots, and demonstrate that they were moving quickly enough to keep pace with the market. In many organizations, simply showing momentum became the strategy. Leadership teams wanted to signal innovation, employees were encouraged to experiment, and new technologies […]
SAP dodges German antitrust investigation over data extraction
SAP is not unfairly preventing enterprises from extracting their data from its systems for use with competitors’ applications, the German Federal Cartel Office (Bundeskartellamt) concluded Thursday after a preliminary investigation. The Bundeskartellamt does not currently intend to initiate abuse proceedings against SAP, although it will continue to monitor developments in what it views as a […]
The SOC’s AI maturity model
The path to next-generation AI Security Operations Centers (SOCs), where AI works hand-in-hand with human analysts, is paved with ambitious goals. This ideal SOC incorporates AI across every task to stop fast-moving threats. But a fully AI-powered SOC isn’t a single deployment or a switch you just flip on. It is a staged rollout that’s […]
Moburst Unveils AI-Driven Mobile Growth Playbook
Moburst, a mobile growth marketing agency, has formalized a mobile-specific approach to Answer Engine Optimization, aimed at helping app publishers get recommended by AI assistants such as ChatGPT, Perplexity, and Google’s AI Overviews, in addition to ranking inside the App Store and Google Play. Why mobile teams are asking this question now A growing share […]

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is “lib-mtop,” an unscoped package with the same name as a […]

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim’s screen. Unit 42 detailed three attack paths against Chrome’s Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest […]

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
The INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its […]

⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, […]

Zero Networks targets AI agent security gaps with network-level ‘Least Agency’ controls
While AI security today is largely focused on restricting what an agent can do, Zero Networks says it has built a failsafe. The company says it can block a compromise midway by adding a network layer protection. On Monday, the company announced the launch of “Least Agency Enforcement,” a new capability designed to implement the […]
KR: Seoul lawmaker criticizes 5,000-won compensation for 4.62 million-person data breach
The Herald Business reports: Seoul Facilities Corp. has drawn criticism over its plan to offer 5,000 won [$3.50 USD] per affected user in response to a personal data breach involving about 4.62 million people, with questions mounting over whether the compensation is adequate. Seoul Metropolitan Council member Im Gyu-ho of the Democratic Party of Korea… […]
UK: Details of 100,000 police staff leaked on the dark web after hack
Bill Curtis reports: The full names and contact details for more than 100,000 police officers and staff have been leaked on the dark web after a hack, The Times can reveal. As part of a major security breach, hackers compromised data belonging to the Ministry of Defence (MoD), the Home Office, National Crime Agency (NCA),… […]
Cyberattack hits Liechtenstein, with 31,000 records stolen
DPA reports: The tiny principality of Liechtenstein has fallen victim to a major cyberattack in which the data of 31,000 people were stolen, the government said on Sunday. The country, which lies between Switzerland and Austria, has a population of around 41,000. The government said it had convened a crisis team led by Prime Minister… […]
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational […]

FOMO in the SOC: Where AI Platforms like Claude Actually Fit
AI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. The conversation has evolved from whether AI belongs in the SOC, to where each type of AI […]
US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States
Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers. The post US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States appeared first on SecurityWeek.
Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations. The post Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking appeared first on SecurityWeek.
Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement. The post Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks appeared first on SecurityWeek.

Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a […]

PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers. The incident, identified on July 26, also exposed some names

Stop depending on heroics and start operationalizing third-party risk
In cybersecurity, third-party risk management normally looks simple on paper: evaluate your vendor, learn the risk, report out on the gaps and weaknesses, transfer to the contract, and continue. Unfortunately, it seldom works that way in practice. In my roles as a CISO, I find my teams in an intermediary position as the compliance and […]

AI is making cybersecurity fundamentals more important than ever
When OpenAI disclosed that one of its models escaped a test environment and broke into Hugging Face’s systems on its own, headlines cast the incident as the start of a new era of AI-driven attacks. But the underlying cause of the incident was a familiar one: a misconfigured sandbox — the same kind of fundamental […]

Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor’s July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented. Thermo Fisher tracks the issue as […]

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version. N-central is the remote monitoring and management platform

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three high-severity security flaws have been disclosed in Hugging Face’s Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk. “These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the
ISC Stormcast For Monday, August 3rd, 2026 https://isc.sans.edu/podcastdetail/10034, (Mon, Aug 3rd)
Post Content
A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN Breach
They advertised and pinky swore “no logs.” But according to research by MysteriumVPN, they logged. Key takeaways from MysteriumVPN: A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database they claim was stolen from SplitVPN (formerly NotVPN), a Russian VPN used to bypass internet blocks. The Mysterium research team obtained… […]
Brinks Home Confirms Data Breach Following ShinyHunters Claim
Guru Baran reports: Brinks Home, one of North America’s largest residential security providers, has confirmed that hackers breached its IT systems after the notorious ShinyHunters extortion group claimed responsibility for stealing nearly five million records tied to the company’s Salesforce environment. The confirmation comes after the threat actors listed “BH Security, LLC (brinkshome.com)” on their… […]
TN: Sumner County Schools provides limited update on data breach
Abbey Nutter reports: Sumner County Schools is still working through a reported network breach that forced the district to delay the start of the 2026-27 school year, officials told Main Street Media. The district reported the data breach during a meeting of the Sumner County Board of Education on July 21, one day after the… […]
Ruby on Rails Patches Critical Vulnerability
The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.
Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments
The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.
Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)
Introduction

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to […]
23-02357.pdf
23-02357.pdf Anonymous (not verified) Sat, 08/01/2026 – 11:45 Case ID 23-02357 Forum FINRA Document Type Award Claimants Windsor Street Capital, LP Respondents Michael Davis M7 Balanced Stage Fund, LLC M7 Asset Management, LLC Syren Capital Advisors LLC Neutrals Keely D. Parr A. Rene Hollyer Jon Michael Fundaro Hearing Site New York, NY Award Document 23-02357.pdf […]
20-00840.pdf
20-00840.pdf Anonymous (not verified) Sat, 08/01/2026 – 11:40 Case ID 20-00840 Forum FINRA Document Type Award Claimants Vincent Yacono Respondents Douglas Guarino Kinan Nimeh Michael Resciniti Rockwell Global Capital LLC Neutrals Patrick R. Westerkamp Hearing Site Syracuse, NY Award Document 20-00840.pdf Documentum DocID ee000223 Award Date Official Fri, 07/31/2026 – 12:00 Related Content Off Claimant […]
26-00191.pdf
26-00191.pdf Anonymous (not verified) Sat, 08/01/2026 – 11:35 Case ID 26-00191 Forum FINRA Document Type Award Claimants Xavier Cortada Respondents Fidelity Brokerage Services LLC Neutrals John James Rubin Hearing Site Atlanta, GA Award Document 26-00191.pdf Documentum DocID abd9d4cb Award Date Official Thu, 07/30/2026 – 12:00 Related Content Off Claimant Representatives Xavier Cortada Respondent Representatives Kevin […]
Sixth Circuit to Rehear Case on FCC Data Breach Rules Case
Jake Neenan reports: A full panel of federal judges will rehear a case that upheld expanded telecom data breach rules. The Federal Communications Commission, now under Republican control, has indicated it’s likely to reverse the rules anyway. But industry groups and GOP lawmakers want the case’s precedent gone too. They told judges on the U.S…. […]
The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years.
Miguel Gomez reports: The biopharmaceutical company Diater, founded in Madrid in 1999, has appeared on the list of victims that the ransomware group DeadLock is disseminating on the dark web. The intrusion affects a company that manages particularly sensitive information of patients and healthcare professionals. The contrast lies in the type of data compromised and… […]
CareCloud Data Breach Impacts Over 350,000
Ionut Arghire reports: Healthcare information technology company CareCloud is notifying at least 350,000 people that their information was stolen in a data breach. The incident involved an electronic health record environment within the CareCloud Health division, which was disrupted on March 16, 2026. CareCloud’s investigation determined that hackers accessed one of its AWS environments between… […]
Suspected cyberattack disrupts Oceanside, California, school district systems
DysruptionHub reports: A suspected cyberattack disrupted work email, internet access, Google Drive and other applications at Oceanside Unified School District in California as officials investigated and worked to restore service. The district confirmed a computer network disruption but did not identify its cause. NC Pipeline reported that a separate district text described the incident as a cyberattack…. […]
AU: GO2 Health medical clinic in Brisbane waited almost three months to alert patients it was hacked
Will Murray reports: Another medical clinic has revealed it has been targeted by hackers, less than a week after Partnered Health announced a major data breach. GO2 Health in Everton Park, in Brisbane’s north, said the clinic’s main email mailbox was accessed in April after a phishing attack. It wasn’t until almost three months later… […]
Mon General Hospital notifies patients of phishing attack and breach
WDTV reports: Monongalia County General Hospital Company, known as Mon General, announced it was recently the victim of a phishing attack that may have compromised the personal and medical information of some patients. Hospital officials say the incident was discovered on May 6, when they identified that a phishing attack had targeted a small number… […]
EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels
When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI. The post EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels appeared first on SecurityWeek.
Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers
Iran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out. The post Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers appeared first on SecurityWeek.
In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
Noteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records. The post In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research appeared first on SecurityWeek.
System Announcement: Maintenance
DataBreaches.net will be undergoing some maintenance and upgrades this weekend and may be unavailable at times. We’ll be back, though! Thank you for your patience. Source

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities. Anyone who visited a site carrying the affected script on July 27 and […]
Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)
Most phishing campaigns rely on the fact that the victim is afraid to loose “something”: money, access to information, … Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could […]

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of […]
AMGEN reports breach to SEC
From Amgen’s filing on July 29 to the Securities and Exchange Commission: Item 1.05 Material Cybersecurity Incidents. In July 2026, Amgen Inc. (the “Company”) identified unauthorized activity involving data stored in cloud environments hosted by third-party cloud service providers. Upon detecting the activity, the Company activated its cybersecurity response plan, implemented containment measures, and engaged… […]
CHARLES SCHWAB & CO., INC.
CHARLES SCHWAB & CO., INC. fnrw-backend Fri, 07/31/2026 – 20:52 MC ID CHAS MC Reporter Type Broker-Dealer MC Paragraph MC Link https://schwab.com/legal/sec-605 MC Last Updated Fri, 07/31/2026 – 20:52