05Aug 2026

Zenity Raises $125 Million in Series C Funding

The AI security company will invest in product innovation, global expansion, and customer experience. The post Zenity Raises $125 Million in Series C Funding appeared first on SecurityWeek.

05Aug 2026

Weaponized Email AI Assistants Could Help Attackers Hijack Accounts

Researchers demonstrate how attackers could abuse built-in email chatbots to evade detection, impersonate trusted employees, compromise executive accounts, and facilitate financial fraud. The post Weaponized Email AI Assistants Could Help Attackers Hijack Accounts appeared first on SecurityWeek.

05Aug 2026

CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout

Russ Kirby, CISO at Ping Identity, shares how passion, courage, and “good enough” thinking shaped his path from HP to the C-suite—and what keeps him up at night. The post CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout appeared first on SecurityWeek.

05Aug 2026

Oligo Raises $60 Million for Runtime Security

The company will use the investment to accelerate product innovation and expand go-to-market operations. The post Oligo Raises $60 Million for Runtime Security appeared first on SecurityWeek.

05Aug 2026

Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer

Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. The post Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer appeared first on SecurityWeek.

05Aug 2026

Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)

Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 2) appeared first on SecurityWeek.

05Aug 2026

Water Sector Cyberattacks Reportedly Hit at Least 12 States

Georgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption. The post Water Sector Cyberattacks Reportedly Hit at Least 12 States appeared first on SecurityWeek.

05Aug 2026

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek.

05Aug 2026

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass. The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek.

05Aug 2026

AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations

In one instance, an unsanctioned model attempted to inject malicious code into an open source repository. The post AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations appeared first on SecurityWeek.

05Aug 2026

One C2 kit. 30 customers. 2 governments

I was mapping the command-and-control infrastructure behind a state-linked intrusion set when the query came back and effectively ended the exercise I thought I was running. The malware resolved its C2 address by reading a smart contract on a public blockchain. Public reporting described one contract. Working from the chain rather than the sample, I […]

05Aug 2026

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The “evil twin” extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have […]

05Aug 2026

Your orchestration framework choice is a security decision, not just an engineering one

Comparisons of LangChain, CrewAI and AutoGen are easy to find — dozens of guides this year cover the same ground: developer experience, ecosystem maturity, how easy it is to wire up multi-agent workflows. None of them ask the question I actually care about: does the framework you pick change how easily your agent gets compromised? […]

05Aug 2026

Why you need a reliable AI agent kill switch

Recent high-profile rogue agent incidents involving OpenAI and Anthropic underscore the fact that organizations can’t put blind trust in their AI guardrails. Moreover, they must able to turn off agents quickly when they deviate from intended behavior — before they can do potentially catastrophic damage. For legal services company Purpose Legal, that includes incorporating a […]

05Aug 2026

Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

An agent running Anthropic’s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK’s AI Security Institute. When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch history to erase the evidence, […]

05Aug 2026

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows – CVE-2026-9198 (CVSS score: 9.8) – A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve […]

05Aug 2026

AI threat report: Rogue agents, workflow attacks

Malicious AI use and threats to AI systems are requiring cyber teams to double down on security fundamentals and rethink the future of their approaches to defense. Newly emerging AI-enabled attacks, proofs of concept, and in-the-wild techniques, as well as the latest AI vulnerability and risk research, present inklings not only about what enterprises presently […]

05Aug 2026

Risky Business #847 -- Oops! Claude's accidental hacking spree

On this week’s show Patrick Gray, and James Wilson are joined by bearded man of leisure Adam Boileau to discuss the week’s cybersecurity news, including: Accidental AI agent hacking sprees have the world’s media freaking out, but we think it’s all pretty funny The bugpocalypse is so chaotic, Microsoft can’t patch fast enough A ColdCard […]

05Aug 2026

QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application […]

05Aug 2026

ISC Stormcast For Wednesday, August 5th, 2026 https://isc.sans.edu/podcastdetail/10038, (Wed, Aug 5th)

Post Content

05Aug 2026

Ruby on Rails critical bug puts every image upload under scrutiny

A new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, CVE-2026-66066, could turn a seemingly innocuous image into a front door to your secrets. Disclosed July 30, the high severity CVE (scored 9.5 out of 10) poses a significant risk to enterprises running apps that handle user-uploaded images in Rails. Dubbed “KindaRails2Shell,” […]

04Aug 2026

ChainDrop credential stealing worm infects over 400 npm packages

A self-propagating worm-like attack is hitting the npm registry, having infected 444 packages from more than a dozen publishers so far. The impact is massive, with the packages affected amounting to more than 2 billion monthly downloads combined. The attack began with the compromise of a GitHub account belonging to Jared Wray, who maintains Keyv, […]

04Aug 2026

23-01170(2).pdf

23-01170(2).pdf Anonymous (not verified) Tue, 08/04/2026 – 17:10 Case ID 23-01170 Forum FINRA Document Type Motion to Vacate Claimants Wells Fargo Clearing Services, LLC Respondents Wade Roberts Neutrals George Pinckney Shingler Hearing Site Atlanta, GA Award Document 23-01170(2).pdf Documentum DocID c3828692 Award Date Official Thu, 09/26/2024 – 12:00 Related Content On Claimant Representatives Keith J. […]

04Aug 2026

25-02217.pdf

25-02217.pdf Anonymous (not verified) Tue, 08/04/2026 – 17:00 Case ID 25-02217 Forum FINRA Document Type Award Claimants Scott Seltzer Respondents J.P. Morgan Securities, LLC Neutrals Lise Gabrielle Hunter Joseph V. Simeri Dineo Coleman Gary Hearing Site Boca Raton, FL Award Document 25-02217.pdf Documentum DocID 7c8700e6 Award Date Official Mon, 08/03/2026 – 12:00 Related Content Off […]

04Aug 2026

VIRTU AMERICAS LLC

VIRTU AMERICAS LLC fnrw-backend Tue, 08/04/2026 – 15:40 MC ID KCGM MC Reporter Type Alternative Trading System MC Paragraph MC Link https://www.virtu.com/about/transparency/rule-605-and-606-reporting/ MC Last Updated Tue, 08/04/2026 – 15:39

04Aug 2026

VIRTU AMERICAS LLC

VIRTU AMERICAS LLC fnrw-backend Tue, 08/04/2026 – 15:39 MC ID ITGP MC Reporter Type Alternative Trading System MC Paragraph MC Link https://www.virtu.com/about/transparency/rule-605-and-606-reporting/ MC Last Updated Tue, 08/04/2026 – 15:39

04Aug 2026

VIRTU AMERICAS LLC

VIRTU AMERICAS LLC fnrw-backend Tue, 08/04/2026 – 15:37 MC ID NITQ MC Reporter Type Single Dealer Trading System MC Paragraph MC Link https://www.virtu.com/about/transparency/rule-605-and-606-reporting/ MC Last Updated Tue, 08/04/2026 – 15:37

04Aug 2026

The AI assurance gap: CIOs need proof that agentic AI controls actually work

Enterprises have spent decades learning how to audit people and software. Agentic AI creates a third category: systems that interpret instructions, call tools and act across workflows without a mature assurance model built around them. In my work as a leader and investor across technology-enabled businesses, I have spent years around automation, cybersecurity, compliance, workflow […]

04Aug 2026

Don’t let your company be fooled by AI efficiency

The scenario isn’t hypothetical: Some of the companies that went furthest in replacing people with AI have had to backtrack. For example, in 2024 Klarna became a European benchmark for what AI could do for a company. Its AI assistant handled two-thirds of customer service chats in its first month, performing the equivalent of 700 full-time agents. As […]

04Aug 2026

Why AI infrastructure needs a new operating model

The next AI infrastructure crisis may come from unmanaged inference capacity. For the past several years, the AI infrastructure conversation centered on one question: how do we get more compute? That made sense. Enterprises needed GPUs, cloud capacity, foundation models and room to experiment. Compute became shorthand for AI readiness. Production AI changes the operating […]

04Aug 2026

20 traits of innovative and invaluable project managers

Projects are becoming more complex, with higher stakes and faster delivery times. At the same time automation and AI are changing how projects are designed, managed, and delivered. Indeed, some pieces of project management are now routinely handled by machines. Some may think that AI and automation will make project managers obsolete, or at least […]

04Aug 2026

The enterprise AI strategy that outlasts any single model

In January of this year, few enterprise tech leaders would have bet on Anthropic over OpenAI. Today, Claude reigns supreme (inspiring a notable 180 by Elon Musk), with Gemini threatening to take market share and introduce pricing models that could flip the leaderboard on its head again. That’s exactly why betting on a single model […]

04Aug 2026

Why meta agents must become the economic intelligence layer of the agentic enterprise

In “Micro and macro agents: The emerging architecture of the agentic enterprise,” I proposed a three-layer architecture for enterprise AI. Micro agents execute specialized tasks. Macro agents orchestrate end-to-end business processes. Meta agents provide governance through monitoring, compliance, security, and human oversight. As enterprises begin deploying thousands — and eventually tens of thousands — of […]

04Aug 2026

AI agents get better at IT ops, but only with humans in the loop

AI agents are performing roughly 1 in 3 actions in enterprise IT workflows (but that share is rising quickly), while human analysts are rejecting about one-quarter of AI-proposed actions (but that rate is falling), according to a new study of tens of thousands of human-AI interactions. Operational data, rather than underlying AI infrastructures, is often […]

04Aug 2026

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. “Greatness supports AiTM [adversary-in-the-middle] credential and

04Aug 2026

Airlock Digital Unveils Agentic AI Control & Governance to Extend Preventative Endpoint Security

Airlock Digital, a leader in preventative endpoint security, today announced Agentic AI Control & Governance at Black Hat USA 2026. The new capabilities build on application control by providing command- and session-level visibility into trusted AI agent behavior, centralized policy management for trusted applications and AI agents, and real-time governance over what trusted AI agents […]

04Aug 2026

Sage Water Resources says Utah saltwater disposal controller intrusion bypassed pump safeguards

Dysruption reports on a critical infrastructure attack in Utah that could have caused more damage than some other recent attacks: Sage Water Resources said workers stopped malicious changes to an automated controller at its oilfield wastewater disposal site near Duchesne, Utah, before the March 15 intrusion caused equipment failure or environmental damage. In an Aug…. […]

04Aug 2026

Florida Man Sentenced for Conspiracy to Commit Wire Fraud

Stolen wallets are still a thing.  From the U.S. Attorney’s Office, Eastern District of Kentucky: July 31, 2026 LEXINGTON, Ky. – An Orlando, Fl., man, Ivory Joe Pruitt, 61, was sentenced on Friday to 63 months imprisonment by U.S. District Judge Robert Wier for conspiracy to commit wire fraud. Pruitt was also ordered to pay $137,392.74… […]

04Aug 2026

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later […]

04Aug 2026

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKE#SCREEN by Securonix Threat

04Aug 2026

Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)

This morning, I noticed specific sources “hunting” for vulnerabilities in URLs that I haven’t noticed before. All of these URLs appear to be associated with diagnostic tools:

04Aug 2026

Republican attorneys general urge OpenAI to preserve records on Hugging Face breach

Miranda Nazzaro reports: More than a dozen Republican attorneys general are calling on OpenAI to preserve records on its models’ recent breach of another company, suggesting the AI firm may have violated state or federal laws in the incident. In a letter sent Monday to OpenAI CEO Sam Altman, 15 attorneys general wrote the ChatGPT-maker may have… […]

04Aug 2026

Swiss federal IT office hit by cyberattack

SwissInfo.ch reports: Following a cyberattack on the SharePoint servers operated by the Federal Office of Information Technology, Systems and Telecommunication (FOITT), access via the internet has been blocked for people outside the federal administration. Around 200 accounts were compromised in the incident. There are no indications of any further data breaches. The unknown attackers are… […]

04Aug 2026

Critical Azure Cosmos DB flaw threatened cross-tenant database takeover

A critical vulnerability in Microsoft Azure’s Cosmos DB database service could have enabled attackers to escape the platform’s Gremlin query sandbox, execute code on shared infrastructure, and ultimately gain access to any customer’s database, including data stores used by Microsoft services such as Entra ID, Teams, and Copilot, according to research published by cloud security […]

04Aug 2026

The top new cybersecurity products at Black Hat USA 2026

Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products. Vendors are increasingly packaging AI into operational workflows, while pairing automation with governance, exposure management, and recovery capabilities aimed at making autonomous security more practical for enterprise environments. […]

04Aug 2026

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability These types of vulnerabilities are a frequent attack […]

04Aug 2026

Acrisure KARR BT and DR-100

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations. The following versions of Acrisure KARR BT and DR-100 are affected: KARR BT firmware <July_20_2026 DR-100 firmware <July_20_2026 CVSS Vendor Equipment Vulnerabilities v3 8.1 Acrisure Acrisure KARR BT and DR-100 Use of Hard-coded Cryptographic Key Background Critical […]

04Aug 2026

Thermo Fisher Applied Biosystems Genetic Analyzers

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results. The following versions of Thermo Fisher Applied Biosystems Genetic Analyzers are affected: Applied Biosystems 3500/3500xL Series Data Collection Software <=4.0.2  Applied Biosystems 3730/3730xL Series Data Collection Software <=5.0.2  […]

04Aug 2026

Google ADK flaws reveal what happens when AI agents trust the wrong message

Security flaws in automated workflows in the GitHub repository for Google’s Agent Development Kit for Python could allow public-facing AI agents to trigger more privileged automation, opening one path to manipulate pull-request reviews and another to expose credentials, according to a report from Pillar Security. The first attack path involved a triage agent that analyzed […]

04Aug 2026

When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted

The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break. Security teams have long estimated risk by ranking attacker sophistication. Nation-state actors sat at one end. Organized criminal groups followed. Inexperienced attackers, dismissed as “script kiddies,” sat at the other end, running public

04Aug 2026

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent. The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so […]

04Aug 2026

Horizon3 Raises $250 Million to Fund Continuing Growth

Venture financing has become an essential factor in growing new business in today’s fast moving economy. Horizon3’s latest funding explains how and why. The post Horizon3 Raises $250 Million to Fund Continuing Growth appeared first on SecurityWeek.

04Aug 2026

River Bank Says Hackers Deleted Data Stolen in Ransomware Attack

The bank holding company was hacked in June, but the investigation into the incident continues. The post River Bank Says Hackers Deleted Data Stolen in Ransomware Attack appeared first on SecurityWeek.

04Aug 2026

Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations

The list of people behind companies, foundations and trusteeships is part of efforts to combat money laundering and terror financing. The post Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations appeared first on SecurityWeek.

04Aug 2026

Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion

The payments giant says BioCatch’s behavioral and device intelligence will help financial institutions combat account takeovers, scams and other forms of digital fraud. The post Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion appeared first on SecurityWeek.

04Aug 2026

Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)

Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 1) appeared first on SecurityWeek.

04Aug 2026

New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems

The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure. The post New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems appeared first on SecurityWeek.

04Aug 2026

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000. The post Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers appeared first on SecurityWeek.

04Aug 2026

150,000 Impacted by Madera Community Hospital Data Breach

An extortion group stole personal, financial, and medical information from the hospital’s network. The post 150,000 Impacted by Madera Community Hospital Data Breach appeared first on SecurityWeek.

04Aug 2026

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login. The post Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks appeared first on SecurityWeek.

04Aug 2026

Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent. The post Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering appeared first on SecurityWeek.

04Aug 2026

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database’s root context, crossing the privilege boundary between a cPanel account and the server’s administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The database bug is tracked as CVE-2026-58048 (CVSS […]

04Aug 2026

Secure AI adoption starts with API best practices

You don’t need to be a fortune teller to understand where enterprise IT is headed. McKinsey reported in November that 62% of global organizations were experimenting, piloting or scaling agentic AI projects. More recently, Gartner forecast that worldwide spending on AI will top $2.59 trillion in 2026 – an increase of 47% from last year. […]

04Aug 2026

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims’ browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. “The first stage drops a steganographic PNG image into the browser’s cache, retrieves its hidden content, and executes […]

04Aug 2026

The Minnesota attackers may hold a better backup of your plant than you do

More than 30 Minnesota community water systems were hit by coordinated cyber activity against their operational technology on July 26 and 27; several lost remote control or deliberately cut it while operators contained the intrusion. The reporting since — including CSO’s own news analysis — has rightly chased two open questions: Who did it, and […]

04Aug 2026

Attackers are crafting malicious AI instruction files to turn your agentic workflows into quiet criminal helpers

AI agents are increasingly being deployed across the enterprise, a rapid adoption that has significantly broadened the organization’s attack surface, turning sharable AI agent resources and configuration files into backdoors, security experts warn. AI-assisted software developers have been increasingly targeted through malicious IDE extensions, rogue MCP servers, and poisoned AI skills, all of which provide […]

04Aug 2026

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows

04Aug 2026

ISC Stormcast For Tuesday, August 4th, 2026 https://isc.sans.edu/podcastdetail/10036, (Tue, Aug 4th)

Post Content

03Aug 2026

EQUITABLE ADVISORS, LLC

EQUITABLE ADVISORS, LLC fnrw-backend Mon, 08/03/2026 – 18:12 MC ID EQHA MC Reporter Type Broker-Dealer MC Paragraph MC Link https://www.lpl.com/disclosures/sec-605-equitable-disclosures.html MC Last Updated Mon, 08/03/2026 – 18:12

03Aug 2026

TRADE-PMR INC.

TRADE-PMR INC. fnrw-backend Mon, 08/03/2026 – 17:29 MC ID TPMR MC Reporter Type Broker-Dealer MC Paragraph MC Link https://www.tradepmr.com/order-routing-disclosures MC Last Updated Mon, 08/03/2026 – 17:29

03Aug 2026

2021069426901 UBS Financial Services Inc. CRD 8174 AWC vrp.pdf

2021069426901 UBS Financial Services Inc. CRD 8174 AWC vrp.pdf Anonymous (not verified) Mon, 08/03/2026 – 17:15 Case ID 2021069426901 Document Number 00747591 Document Type AWCs (Letters of Acceptance, Waiver, and Consent) Action Date Fri, 07/31/2026 – 12:00 Related Content Off Attachment 2021069426901 UBS Financial Services Inc. CRD 8174 AWC vrp.pdf

03Aug 2026

26-00488.pdf

26-00488.pdf Anonymous (not verified) Mon, 08/03/2026 – 17:10 Case ID 26-00488 Forum FINRA Document Type Award Claimants Michael Renshaw Respondents Robinhood Securities, LLC Neutrals Chandler R. Bridges Hearing Site Atlanta, GA Award Document 26-00488.pdf Documentum DocID 5c5483ca Award Date Official Mon, 08/03/2026 – 12:00 Related Content Off Claimant Representatives Michael J. Renshaw Respondent Representatives Michael […]

03Aug 2026

26-00144.pdf

26-00144.pdf Anonymous (not verified) Mon, 08/03/2026 – 17:10 Case ID 26-00144 Forum FINRA Document Type Award Claimants Paula Gomoll Respondents Charles Schwab & Co., Inc. Cetera Financial Specialists LLC Eric Wurtel Neutrals Mark W Solock Hearing Site Chicago, IL Award Document 26-00144.pdf Documentum DocID 14dab4c2 Award Date Official Mon, 08/03/2026 – 12:00 Related Content Off […]

03Aug 2026

AI can do your tasks. That doesn’t mean it will do your job

Much of the conversation around AI and work has centered on a single question: Will AI take my job? It’s an understandable concern. Every week AI becomes increasingly more capable. We see AI summarizing meetings, generating content, analyzing data, writing software and automating workflows that once required significant human effort. Agentic AI is also becoming […]

03Aug 2026

12 business analyst certifications to level up your career

Business analysts help organizations make the most of the data they collect by finding trends, patterns, and errors that might otherwise go unnoticed. Successful business analysts have the skills to work with data, the acumen to understand the business side of the organization, and the ability to communicate that information to people outside of IT. […]

03Aug 2026

Frontier AI will not break finance. Slow cyber decisions will

The scariest thing about frontier AI is that it gives lazy criminals better legs. That sounds flippant until you watch how cyber failure works. I have seen that weakness in many costumes: A server waiting for a patch, an access path nobody wants to touch, a supplier marked “low risk” because the contract said so, […]

03Aug 2026

CIOs risk being sidelined in enterprise AI initiatives

The AI revolution has created new opportunities for CIOs, with expanded responsibilities and more authority, but some observers see the opposite happening at some organizations. While many CIOs have become the main executive leading AI strategy and initiatives, some organizations have set the responsibility for AI deployment and adoption with another executive. That puts CIOs […]

03Aug 2026

The missing role in every enterprise AI strategy: The analytics engineer

Every enterprise AI strategy these days has mostly the same core cast: Software engineers who log online events data, data engineers who move data from online to offline data warehouses, data scientists who build machine learning models, AI/ML engineers who deploy these models to production systems and data analysts who consume these data outputs and […]

03Aug 2026

AI’s measurement crisis is over. The translation crisis is next

Last fall, you couldn’t open a business publication without tripping over some version of the same headline: where is the ROI for AI? The anchor for most of that coverage was MIT’s “GenAI Divide” report, which found that despite $30 to 40 billion in enterprise generative AI spending, 95% of pilots delivered no measurable P&L […]

03Aug 2026

Companies winning with AI operate differently. Here’s how.

The first phase of the AI race was largely about access. Companies rushed to adopt tools, launch pilots, and demonstrate that they were moving quickly enough to keep pace with the market. In many organizations, simply showing momentum became the strategy. Leadership teams wanted to signal innovation, employees were encouraged to experiment, and new technologies […]

03Aug 2026

SAP dodges German antitrust investigation over data extraction

SAP is not unfairly preventing enterprises from extracting their data from its systems for use with competitors’ applications, the German Federal Cartel Office (Bundeskartellamt) concluded Thursday after a preliminary investigation. The Bundeskartellamt does not currently intend to initiate abuse proceedings against SAP, although it will continue to monitor developments in what it views as a […]

03Aug 2026

The SOC’s AI maturity model

The path to next-generation AI Security Operations Centers (SOCs), where AI works hand-in-hand with human analysts, is paved with ambitious goals. This ideal SOC incorporates AI across every task to stop fast-moving threats. But a fully AI-powered SOC isn’t a single deployment or a switch you just flip on. It is a staged rollout that’s […]

03Aug 2026

Moburst Unveils AI-Driven Mobile Growth Playbook

Moburst, a mobile growth marketing agency, has formalized a mobile-specific approach to Answer Engine Optimization, aimed at helping app publishers get recommended by AI assistants such as ChatGPT, Perplexity, and Google’s AI Overviews, in addition to ranking inside the App Store and Google Play. Why mobile teams are asking this question now A growing share […]

03Aug 2026

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is “lib-mtop,” an unscoped package with the same name as a […]

03Aug 2026

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim’s screen. Unit 42 detailed three attack paths against Chrome’s Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest […]

03Aug 2026

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its […]

03Aug 2026

⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, […]

03Aug 2026

Zero Networks targets AI agent security gaps with network-level ‘Least Agency’ controls

While AI security today is largely focused on restricting what an agent can do, Zero Networks says it has built a failsafe. The company says it can block a compromise midway by adding a network layer protection. On Monday, the company announced the launch of “Least Agency Enforcement,” a new capability designed to implement the […]

03Aug 2026

KR: Seoul lawmaker criticizes 5,000-won compensation for 4.62 million-person data breach

The Herald Business reports: Seoul Facilities Corp. has drawn criticism over its plan to offer 5,000 won [$3.50 USD] per affected user in response to a personal data breach involving about 4.62 million people, with questions mounting over whether the compensation is adequate. Seoul Metropolitan Council member Im Gyu-ho of the Democratic Party of Korea… […]

03Aug 2026

UK: Details of 100,000 police staff leaked on the dark web after hack

Bill Curtis reports: The full names and contact details for more than 100,000 police officers and staff have been leaked on the dark web after a hack, The Times can reveal. As part of a major security breach, hackers compromised data belonging to the Ministry of Defence (MoD), the Home Office, National Crime Agency (NCA),… […]

03Aug 2026

Cyberattack hits Liechtenstein, with 31,000 records stolen

DPA reports: The tiny principality of Liechtenstein has fallen victim to a major cyberattack in which the data of 31,000 people were stolen, the government said on Sunday. The country, which lies between Switzerland and Austria, has a population of around 41,000. The government said it had convened a crisis team led by Prime Minister… […]

03Aug 2026

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational […]

03Aug 2026

FOMO in the SOC: Where AI Platforms like Claude Actually Fit

AI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. The conversation has evolved from whether AI belongs in the SOC, to where each type of AI […]

03Aug 2026

US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States

Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers. The post US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States appeared first on SecurityWeek.

03Aug 2026

Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking

Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations. The post Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking appeared first on SecurityWeek.

03Aug 2026

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks

The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement. The post Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks appeared first on SecurityWeek.

03Aug 2026

Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a […]

03Aug 2026

PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web

The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers. The incident, identified on July 26, also exposed some names

03Aug 2026

Stop depending on heroics and start operationalizing third-party risk

In cybersecurity, third-party risk management normally looks simple on paper: evaluate your vendor, learn the risk, report out on the gaps and weaknesses, transfer to the contract, and continue. Unfortunately, it seldom works that way in practice. In my roles as a CISO, I find my teams in an intermediary position as the compliance and […]

03Aug 2026

AI is making cybersecurity fundamentals more important than ever

When OpenAI disclosed that one of its models escaped a test environment and broke into Hugging Face’s systems on its own, headlines cast the incident as the start of a new era of AI-driven attacks. But the underlying cause of the incident was a familiar one: a misconfigured sandbox — the same kind of fundamental […]

03Aug 2026

Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable

Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor’s July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented. Thermo Fisher tracks the issue as […]

03Aug 2026

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version. N-central is the remote monitoring and management platform

03Aug 2026

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

Three high-severity security flaws have been disclosed in Hugging Face’s Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk. “These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the

03Aug 2026

ISC Stormcast For Monday, August 3rd, 2026 https://isc.sans.edu/podcastdetail/10034, (Mon, Aug 3rd)

Post Content

02Aug 2026

A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN Breach

They advertised and pinky swore “no logs.” But according to research by MysteriumVPN, they logged. Key takeaways from MysteriumVPN: A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database they claim was stolen from SplitVPN (formerly NotVPN), a Russian VPN used to bypass internet blocks. The Mysterium research team obtained… […]

02Aug 2026

Brinks Home Confirms Data Breach Following ShinyHunters Claim

Guru Baran reports: Brinks Home, one of North America’s largest residential security providers, has confirmed that hackers breached its IT systems after the notorious ShinyHunters extortion group claimed responsibility for stealing nearly five million records tied to the company’s Salesforce environment. The confirmation comes after the threat actors listed “BH Security, LLC (brinkshome.com)” on their… […]

02Aug 2026

TN: Sumner County Schools provides limited update on data breach

Abbey Nutter reports: Sumner County Schools is still working through a reported network breach that forced the district to delay the start of the 2026-27 school year, officials told Main Street Media. The district reported the data breach during a meeting of the Sumner County Board of Education on July 21, one day after the… […]

02Aug 2026

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

02Aug 2026

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

02Aug 2026

Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)

Introduction

01Aug 2026

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to […]

01Aug 2026

23-02357.pdf

23-02357.pdf Anonymous (not verified) Sat, 08/01/2026 – 11:45 Case ID 23-02357 Forum FINRA Document Type Award Claimants Windsor Street Capital, LP Respondents Michael Davis M7 Balanced Stage Fund, LLC M7 Asset Management, LLC Syren Capital Advisors LLC Neutrals Keely D. Parr A. Rene Hollyer Jon Michael Fundaro Hearing Site New York, NY Award Document 23-02357.pdf […]

01Aug 2026

20-00840.pdf

20-00840.pdf Anonymous (not verified) Sat, 08/01/2026 – 11:40 Case ID 20-00840 Forum FINRA Document Type Award Claimants Vincent Yacono Respondents Douglas Guarino Kinan Nimeh Michael Resciniti Rockwell Global Capital LLC Neutrals Patrick R. Westerkamp Hearing Site Syracuse, NY Award Document 20-00840.pdf Documentum DocID ee000223 Award Date Official Fri, 07/31/2026 – 12:00 Related Content Off Claimant […]

01Aug 2026

26-00191.pdf

26-00191.pdf Anonymous (not verified) Sat, 08/01/2026 – 11:35 Case ID 26-00191 Forum FINRA Document Type Award Claimants Xavier Cortada Respondents Fidelity Brokerage Services LLC Neutrals John James Rubin Hearing Site Atlanta, GA Award Document 26-00191.pdf Documentum DocID abd9d4cb Award Date Official Thu, 07/30/2026 – 12:00 Related Content Off Claimant Representatives Xavier Cortada Respondent Representatives Kevin […]

01Aug 2026

Sixth Circuit to Rehear Case on FCC Data Breach Rules Case

Jake Neenan reports: A full panel of federal judges will rehear a case that upheld expanded telecom data breach rules. The Federal Communications Commission, now under Republican control, has indicated it’s likely to reverse the rules anyway. But industry groups and GOP lawmakers want the case’s precedent gone too. They told judges on the U.S…. […]

01Aug 2026

The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years.

Miguel Gomez reports: The biopharmaceutical company Diater, founded in Madrid in 1999, has appeared on the list of victims that the ransomware group DeadLock is disseminating on the dark web. The intrusion affects a company that manages particularly sensitive information of patients and healthcare professionals. The contrast lies in the type of data compromised and… […]

01Aug 2026

CareCloud Data Breach Impacts Over 350,000

Ionut Arghire reports: Healthcare information technology company CareCloud is notifying at least 350,000 people that their information was stolen in a data breach. The incident involved an electronic health record environment within the CareCloud Health division, which was disrupted on March 16, 2026. CareCloud’s investigation determined that hackers accessed one of its AWS environments between… […]

01Aug 2026

Suspected cyberattack disrupts Oceanside, California, school district systems

DysruptionHub reports: A suspected cyberattack disrupted work email, internet access, Google Drive and other applications at Oceanside Unified School District in California as officials investigated and worked to restore service. The district confirmed a computer network disruption but did not identify its cause. NC Pipeline reported that a separate district text described the incident as a cyberattack…. […]

01Aug 2026

AU: GO2 Health medical clinic in Brisbane waited almost three months to alert patients it was hacked

Will Murray reports: Another medical clinic has revealed it has been targeted by hackers, less than a week after Partnered Health announced a major data breach. GO2 Health in Everton Park, in Brisbane’s north, said the clinic’s main email mailbox was accessed in April after a phishing attack. It wasn’t until almost three months later… […]

01Aug 2026

Mon General Hospital notifies patients of phishing attack and breach

WDTV reports: Monongalia County General Hospital Company, known as Mon General, announced it was recently the victim of a phishing attack that may have compromised the personal and medical information of some patients. Hospital officials say the incident was discovered on May 6, when they identified that a phishing attack had targeted a small number… […]

01Aug 2026

EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels

When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI. The post EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels appeared first on SecurityWeek.

01Aug 2026

Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers

Iran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out. The post Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers appeared first on SecurityWeek.

01Aug 2026

In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research

Noteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records. The post In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research appeared first on SecurityWeek.

01Aug 2026

System Announcement: Maintenance

DataBreaches.net will be undergoing some maintenance and upgrades this weekend and may be unavailable at times. We’ll be back, though! Thank you for your patience. Source

01Aug 2026

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities. Anyone who visited a site carrying the affected script on July 27 and […]

01Aug 2026

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose “something”: money, access to information, … Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

01Aug 2026

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could […]

01Aug 2026

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of […]

01Aug 2026

AMGEN reports breach to SEC

From Amgen’s filing on July 29 to the Securities and Exchange Commission: Item 1.05 Material Cybersecurity Incidents. In July 2026, Amgen Inc. (the “Company”) identified unauthorized activity involving data stored in cloud environments hosted by third-party cloud service providers. Upon detecting the activity, the Company activated its cybersecurity response plan, implemented containment measures, and engaged… […]

01Aug 2026

CHARLES SCHWAB & CO., INC.

CHARLES SCHWAB & CO., INC. fnrw-backend Fri, 07/31/2026 – 20:52 MC ID CHAS MC Reporter Type Broker-Dealer MC Paragraph MC Link https://schwab.com/legal/sec-605 MC Last Updated Fri, 07/31/2026 – 20:52