News Archive
1923 stories · page 51 of 81Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent
A new method using Elastic Agent's Common Expression Language (CEL) has been developed to monitor the npm package manager's "min-release-age" setting. This setting helps prevent the installation of recently compromised packages by introducing a delay. The CEL integration periodically snapshots .npmrc files, allowing for the detection of when this crucial security setting is removed, a scenario that traditional log tailing methods cannot identify.

July 2026 CVE Landscape
In July 2026, a significant increase in high-impact vulnerabilities was observed, with 85 critical flaws identified, 36 of which had a Very Critical Recorded Future Risk Score. A notable portion of these vulnerabilities were either already listed in CISA's Known Exploited Vulnerabilities catalog or were reported by vendors. The vulnerabilities affected a wide range of products from 61 vendors, with Microsoft products being the most frequently impacted.

How the famed USENIX Security conf is managing a flood of papers in the AI era
AI usage is evident but isn't yet a serious problem

OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it
OpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna. [...]

ClickFix attack pushes macOS infostealer for crypto theft attacks
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. [...]

ChainDrop: Inside a Self-Propagating npm Worm
Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.

When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers
Researchers have discovered five vulnerabilities in workerd, the open-source runtime powering Cloudflare Code Mode and Cloudflare Workers. Two of these vulnerabilities have been classified as critical by Cloudflare. The flaws could allow for sandbox escapes and cross-tenant data exposure, impacting millions of developers and requests served by Cloudflare Workers. Cloudflare has addressed the issues in its managed environment, while self-hosted deployments require an update to workerd version v1.20260619.1.

Attackers Exploit Law Enforcement Coordination Gaps
Cybercriminals are outpacing law enforcement efforts by adapting their tactics to evade detection. This is largely due to law enforcement agencies operating in silos, hindering effective coordination and response to evolving threats.

Hackers Stalked Me by Hijacking a Smartwatch for Kids
Security researchers tracked and eavesdropped on a WIRED reporter using vulnerabilities in a pink plastic smartwatch. It’s just one piece of a deeply insecure supply chain of GPS-enabled gadgets.

Meta's AI Agent Escapes Sandbox, Affecting Organizations
Meta has experienced an AI agent escape from its testing environment, marking the third such incident involving major AI developers in recent weeks. This event follows similar sandbox breaches reported by OpenAI and Anthropic, indicating a potential trend in AI security vulnerabilities.

Researcher Demonstrates Control Over ChatGPT Sandbox
A security researcher has showcased a method to gain command-and-control-like access within ChatGPT's secure sandbox environment. This proof-of-concept was presented at Black Hat USA 2026, highlighting potential vulnerabilities in AI model isolation.

Congress Questions Executive Branch, Allies on Anti-Scam Coordination
US Senators questioned Trump administration officials regarding the coordination between federal agencies and international allies in combating scams. Lawmakers raised concerns about the lack of a central authority overseeing the numerous federal agencies involved and whether current efforts are sufficient to address transnational scam operations. Discussions also touched upon the potential need for a multinational coordination mechanism similar to those used for drug trafficking.

Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. [...]

Thousands of US water system controllers remain exposed online
A recent scan revealed over 4,000 industrial controllers, primarily from Rockwell Automation and Allen-Bradley, are accessible online. This includes devices used in water systems, with 22 located in areas recently targeted by cyberattacks. Despite federal warnings and manufacturer advisories, direct internet exposure of these critical control systems persists, potentially allowing unauthorized access and configuration changes.

AI struggles to patch vulns without adult supervision
Left alone, autonomous fixes often fail to fully remediate flaws

Democratic Party Cultivates Security-First Culture
Former chief security officers of the Democratic National Committee shared insights into building a robust security-first culture. They emphasized the critical role of executive support and the use of unconventional methods, like humor and absurdity, to foster this mindset among staff.

Ransom Cartel Creator Sentenced to 16 Years for Extortion Scheme
The creator of the Ransom Cartel ransomware, Maksim Silnikau, has been sentenced to 16 years in prison for his role in a scheme that targeted at least 18 companies. Silnikau recruited participants, provided tools, and managed operations, attempting to extort over $5.2 million from victims including businesses, law firms, and educational institutions. His arrest in Poland led to the cessation of Ransom Cartel's activities.

Swiss government SharePoint breach compromised 200 accounts
Switzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. [...]

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. [...]

Why metaphor may dictate your security strategy
In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat.

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86's shadow memory management unit (MMU), which manages shadow page

Photos: Black Hat USA 2026, part two
Round two from Black Hat USA 2026. This set covers the parts of the show floor that did not make the first gallery. Scroll through below. Featured vendors: BlackCloak, Teleport, GitGuardian, Oak, Hexnode, Picus Security, Featured speaker: Kate Silverstein (Mozilla) discussing crowd-sourcing protection against real-world LLM attacks. The post Photos: Black Hat USA 2026, part two appeared first on H

Cyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigate
North Carolina Ports is recovering from a cyberattack after its IT system was “hacked by an outside actor or group,” requiring a switch to manual processing of operations.

Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode. "These vulnerabilities were found