Cyber Security
Cybersecurity
Unit 42 Details Pass-ta-key Attacks on Google-Synced Passkeys
Gabby Lee
August 4, 2026
Unit 42 reveals three Pass-ta-key attacks that let malware hijack Google-synced passkeys on Windows by abusing Chrome's TPM trust and cloud authenticator flows.
Application Security
Malicious npm Packages Deliver RAT to Alibaba Developer Tools
Andrew Doyle
August 4, 2026
Socket found 18 malicious npm packages impersonating Alibaba developer tools that deliver a cross-platform RAT with remote control and data-theft capabilities.
Application Security
Poisoned Xanadu mrmustard Package Steals SSH Keys and AWS Credentials
Andrew Doyle
August 4, 2026
Threat actors poisoned Xanadu's mrmustard 0.7.4 on PyPI with an info-stealer that exfiltrates SSH keys and AWS credentials from research and HPC systems.
Cybersecurity
Leaked DarkSword Kit Deploys GHOSTBLADE Stealer on iOS Devices
Gabby Lee
August 4, 2026
Censys found a Chinese-speaking actor using the leaked DarkSword exploit kit to deploy the GHOSTBLADE info-stealer on iOS devices and steal credentials.
Cybersecurity
ExfilSquad Leaks Contact Data of 100,000 UK Police Officers
Mitchell Langley
August 4, 2026
ExfilSquad leaked contact data of over 100,000 UK police and staff in a Police National Legal Database breach, enabling phishing against named officers.
Cybersecurity
DOUBLECUP ClickFix Loader Hides Malware in Browser Cache Images
Mitchell Langley
August 4, 2026
The DOUBLECUP Russian loader-as-a-service uses ClickFix prompts and PNG steganography in browser cache to deliver CountLoader and the DeviceManager RAT.
Cybersecurity
Fake Roblox Xeno Executor Installers Deliver Info-Stealer RAT
Andrew Doyle
August 4, 2026
Bitdefender found fake Roblox Xeno Executor installers pushing a Java RAT that steals browser data, crypto wallets, game tokens, and payment data from players.
Cybersecurity
Liechtenstein Register Breach Exposes Data of 31,000 People
Mitchell Langley
August 4, 2026
A cyberattack accessed Liechtenstein's beneficial-ownership register, exposing data on about 31,000 people behind companies and foundations, officials said.
Cybersecurity
UKGI Left Officials’ Contact Details Exposed for 40 Hours
Gabby Lee
August 4, 2026
UK Government Investments admitted an employee left a file with 51 government officials' names and work email addresses publicly accessible for 40 hours.
Cybersecurity
INC Ransomware Becomes Top Exploiter of SonicWall SMA1000 Zero-Days
Gabby Lee
August 3, 2026
INC Ransomware is now the most active group exploiting SonicWall SMA1000 zero-days, breaching victims in the US, Australia, UAE, Colombia, and Switzerland.
CVE Vulnerability Alerts
Thermo Fisher Patches DNA File Tampering Flaw CVE-2026-17583
Andrew Doyle
August 3, 2026
Thermo Fisher patched CVE-2026-17583 in Applied Biosystems DNA-testing software, allowing forensic evidence file alterations to pass with little detection.
Application Security
FaceHugger Flaws in Hugging Face Diffusers Bypass trust_remote_code
Gabby Lee
August 3, 2026
FaceHugger flaws in Hugging Face Diffusers bypass trust_remote_code and let malicious model repositories execute arbitrary code when models are loaded.
Application Security
Hackers Poison Adform Script to Rewrite Crypto Wallet Addresses
Mitchell Langley
August 3, 2026
Attackers tampered with Adform's trackpoint script, rewriting crypto wallet addresses across customer pages to divert payments to attacker-controlled wallets.
Cybersecurity
Coldcard Firmware Flaw Linked to $88.6M Bitcoin Sweep
Gabby Lee
August 3, 2026
A Coldcard firmware flaw that sent seed generation to a software PRNG is tied to an $88.6 million Bitcoin sweep across 4,585 drained wallet addresses.
Cybersecurity
Microsoft Links Hotel Wi-Fi Attacks to Storm-2945 Midnight Blizzard
Mitchell Langley
August 3, 2026
Microsoft ties CaptiveCrunch hotel Wi-Fi attacks to Storm-2945, a Midnight Blizzard sub-cluster pushing fake updates that steal Microsoft 365 credentials.
CVE Vulnerability Alerts
N-able Warns Attackers Reached Managed Endpoints via N-central Flaw
Andrew Doyle
August 3, 2026
N-able warns attackers exploited CVE-2026-18577 to take over N-central servers and reach managed endpoints, planting Cloudflare tunnels for persistent access.
Cybersecurity
US Water Sector Attacks Spread to Seven States as Iran Link Emerges
Gabby Lee
August 3, 2026
Cyberattacks on US water and wastewater systems have spread to at least seven states, as investigators examine possible Iranian involvement in the campaign.
Blog
Cloud Access Security Broker (CASB) Explained: Architecture and Uses
Gabby Lee
August 3, 2026
Learn what a cloud access security broker (CASB) is, how its architecture works, key use cases, and how CASB fits into modern multi-cloud security.
Cybersecurity
DPRK macOS Malvertising Uses ClickFix to Steal Wallets and Cloud Keys
Mitchell Langley
July 31, 2026
North Korea-linked actors use fake macOS update pages and ClickFix prompts to deploy malware that drains crypto wallets and steals SSH, AWS, and Azure keys.
Application Security
Wiz CosmosEscape Chain Exposed Azure Cosmos DB Tenant Keys
Andrew Doyle
July 31, 2026
Wiz researchers showed an Azure Cosmos DB Gremlin sandbox escape could expose a platform-wide signing key that unlocks any tenant account's primary keys.
Cybersecurity
Unit 42 Details Pass-ta-key Attacks on Google-Synced Passkeys
Gabby Lee
August 4, 2026
Application Security
Poisoned Xanadu mrmustard Package Steals SSH Keys and AWS Credentials
Andrew Doyle
August 4, 2026
Cybersecurity
INC Ransomware Becomes Top Exploiter of SonicWall SMA1000 Zero-Days
Gabby Lee
August 3, 2026
TOP CYBERSECURITY HEADLINES
This Week’s Security Spotlight
Application Security
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
Andrew Doyle
July 31, 2026
CVE Vulnerability Alerts
Cisco Secure FMC Zero-Day Added to CISA KEV Under Active Attack
Mitchell Langley
July 30, 2026
Application Security
VMware ESXi VM Escape CVE-2026-47876 Patched Alongside Four More Flaws
Gabby Lee
July 29, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
Leaked DarkSword Kit Deploys GHOSTBLADE Stealer on iOS Devices
August 4, 2026
Censys found a Chinese-speaking actor using the leaked DarkSword exploit kit to deploy the GHOSTBLADE info-stealer on iOS devices and steal credentials.
ExfilSquad Leaks Contact Data of 100,000 UK Police Officers
August 4, 2026
ExfilSquad leaked contact data of over 100,000 UK police and staff in a Police National Legal Database breach, enabling phishing against named officers.
DOUBLECUP ClickFix Loader Hides Malware in Browser Cache Images
August 4, 2026
The DOUBLECUP Russian loader-as-a-service uses ClickFix prompts and PNG steganography in browser cache to deliver CountLoader and the DeviceManager RAT.
Fake Roblox Xeno Executor Installers Deliver Info-Stealer RAT
August 4, 2026
Bitdefender found fake Roblox Xeno Executor installers pushing a Java RAT that steals browser data, crypto wallets, game tokens, and payment data from players.
Liechtenstein Register Breach Exposes Data of 31,000 People
August 4, 2026
A cyberattack accessed Liechtenstein's beneficial-ownership register, exposing data on about 31,000 people behind companies and foundations, officials said.
UKGI Left Officials’ Contact Details Exposed for 40 Hours
August 4, 2026
UK Government Investments admitted an employee left a file with 51 government officials' names and work email addresses publicly accessible for 40 hours.
INC Ransomware Becomes Top Exploiter of SonicWall SMA1000 Zero-Days
August 3, 2026
INC Ransomware is now the most active group exploiting SonicWall SMA1000 zero-days, breaching victims in the US, Australia, UAE, Colombia, and Switzerland.
Thermo Fisher Patches DNA File Tampering Flaw CVE-2026-17583
August 3, 2026
Thermo Fisher patched CVE-2026-17583 in Applied Biosystems DNA-testing software, allowing forensic evidence file alterations to pass with little detection.
FaceHugger Flaws in Hugging Face Diffusers Bypass trust_remote_code
August 3, 2026
FaceHugger flaws in Hugging Face Diffusers bypass trust_remote_code and let malicious model repositories execute arbitrary code when models are loaded.
Hackers Poison Adform Script to Rewrite Crypto Wallet Addresses
August 3, 2026
Attackers tampered with Adform's trackpoint script, rewriting crypto wallet addresses across customer pages to divert payments to attacker-controlled wallets.
Coldcard Firmware Flaw Linked to $88.6M Bitcoin Sweep
August 3, 2026
A Coldcard firmware flaw that sent seed generation to a software PRNG is tied to an $88.6 million Bitcoin sweep across 4,585 drained wallet addresses.
Microsoft Links Hotel Wi-Fi Attacks to Storm-2945 Midnight Blizzard
August 3, 2026
Microsoft ties CaptiveCrunch hotel Wi-Fi attacks to Storm-2945, a Midnight Blizzard sub-cluster pushing fake updates that steal Microsoft 365 credentials.
N-able Warns Attackers Reached Managed Endpoints via N-central Flaw
August 3, 2026
N-able warns attackers exploited CVE-2026-18577 to take over N-central servers and reach managed endpoints, planting Cloudflare tunnels for persistent access.
US Water Sector Attacks Spread to Seven States as Iran Link Emerges
August 3, 2026
Cyberattacks on US water and wastewater systems have spread to at least seven states, as investigators examine possible Iranian involvement in the campaign.
Cloud Access Security Broker (CASB) Explained: Architecture and Uses
August 3, 2026
Learn what a cloud access security broker (CASB) is, how its architecture works, key use cases, and how CASB fits into modern multi-cloud security.
DPRK macOS Malvertising Uses ClickFix to Steal Wallets and Cloud Keys
July 31, 2026
North Korea-linked actors use fake macOS update pages and ClickFix prompts to deploy malware that drains crypto wallets and steals SSH, AWS, and Azure keys.
Wiz CosmosEscape Chain Exposed Azure Cosmos DB Tenant Keys
July 31, 2026
Wiz researchers showed an Azure Cosmos DB Gremlin sandbox escape could expose a platform-wide signing key that unlocks any tenant account's primary keys.
AnySign4PC Zero-Day Watering Holes Hit 72 South Korean Organizations
July 31, 2026
A state-sponsored campaign used hacked South Korean websites to exploit an AnySign4PC zero-day and infect visitors with SIGNBT and COPPERHEDGE backdoors.
Silver Fox BYOVD Chain Deploys ValleyRAT at Japanese Manufacturer
July 31, 2026
Silver Fox used a new three-driver BYOVD attack chain and dual watchdog persistence to deliver ValleyRAT at a Japanese manufacturer through invoice lures.
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
July 31, 2026
Anthropic said Claude models breached three real organizations during evaluations, including publishing PyPI malware that stole a security vendor's credentials.

























