SecOps News
Get this as an RSS feed
- Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse (13 minutes ago)
- DeadLock ransomware uses blockchain to resist infrastructure takedown (3 hours ago)
- Signal adds an extra layer of security to make sure you’re actually chatting with the right person (3 hours ago)
- 421 bugs in Microsoft’s Patch Tuesday release, and the Norks have already attacked one (3 hours ago)
- Microsoft Plugs Nearly 400 Security Holes (4 hours ago)
- Sandworm hackers target IT pros with trojanized WireGuard VPN client (4 hours ago)
- Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack (5 hours ago)
- Incident with GraphQL API Requests (5 hours ago)
- Cisco warns of ASA and FTD VPN flaw exploited to crash devices (5 hours ago)
- Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing (5 hours ago)
- Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client (6 hours ago)
- August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day (6 hours ago)
- Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands (6 hours ago)
- Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees (6 hours ago)
- Microsoft releases Windows 10 KB5120249 extended security update (7 hours ago)
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days (7 hours ago)
- Windows 11 KB5121003 & KB5120240 cumulative updates released (7 hours ago)
- Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws (8 hours ago)
- Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE (8 hours ago)
- DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt (8 hours ago)
- DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi (9 hours ago)
- Wesco confirms security incident after ExfilSquad claims data theft (9 hours ago)
- Zoom Patches Zero-Click Code Execution Vulnerability (9 hours ago)
- Two wars and a World Cup lead to epic DDoS attacks on publishers (9 hours ago)
- The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It (10 hours ago)
- Device Bound Session Credentials lands in Chrome on macOS (11 hours ago)
- SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities (11 hours ago)
- US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ (11 hours ago)
- Mozilla updates GPG signing key for Firefox releases after exposure (12 hours ago)
- Vague Task, Total Access: When AI Delegation Becomes a Security Risk (12 hours ago)
- OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development (12 hours ago)
- DDoS attacks over 1 Tbps surged fivefold in the second quarter (12 hours ago)
- Deepfake hiccup unmasks suspected digital certificate fraudster (13 hours ago)
- CISA: Microsoft SharePoint flaw now exploited in ransomware attacks (13 hours ago)
- A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices (13 hours ago)
- Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo (13 hours ago)
- Corma Raises $60 Million for Defensive Cybersecurity AI Model (13 hours ago)
- Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub (13 hours ago)
- Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers (13 hours ago)
- Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities (14 hours ago)
- Cisco warns of high-severity ClamAV flaws with public exploits (14 hours ago)
- Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11 (14 hours ago)
- Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets (15 hours ago)
- GRC Solutions Partners with Defense.com™ to Help Businesses Take Control of Cyber Risk (15 hours ago)
- Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption (15 hours ago)
- US and South Korea warn of Gunra ransomware targeting govt agencies (15 hours ago)
- OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber (15 hours ago)
- Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G (15 hours ago)
- Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks (16 hours ago)
- Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine (18 hours ago)
- BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins (19 hours ago)
- Disruption with Copilot for access to some models (1 days ago)
- DEF CON hackers add new muscle to water utility protection (1 days ago)
- Disruption with creation of fine grained personal access tokens (1 days ago)
- Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development (1 days ago)
- North Korean spies are running local LLMs to cause AI mischief (1 days ago)
- Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list (1 days ago)
- China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw (1 days ago)
- Everything I Learned Shipping Device Bound Session Credentials (1 days ago)
- ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors (1 days ago)
- Attackers pick Levi’s pockets in social engineering attack (1 days ago)
- Wetherspoons bars smart glasses from filming customers (1 days ago)
- Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development (1 days ago)
- New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA (1 days ago)
- Cyber vulnerability sweep picks up Royal Navy drones sending data to China (1 days ago)
- TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore (1 days ago)
- Framework loses customer data in Metabase zero-day attack (1 days ago)
- Claude Code puts auto mode in the driver’s seat (1 days ago)
- Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials (1 days ago)
- OpenAI’s Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause (1 days ago)
- Advertisers are trying to influence AI bots with secret ads (1 days ago)
- KR: 3Pro TV Data Breach Exposes 460,000 Records, Including 2,979 Bank Accounts (2 days ago)
- Ransomware gangs skip the CEO, head straight for the 40-something IT manager (2 days ago)
- Alcon - 218,395 breached accounts (2 days ago)
- Ransomware gangs skip the CEO, head straight for the 40-something IT manager (2 days ago)
- City of Suisun declares local emergency after cyberattack downs 911 dispatch system (3 days ago)
- Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default (3 days ago)
- City of Coweta refuses to pay ransom after system-wide cyberattack (3 days ago)
- Brinks Home - 732,162 breached accounts (3 days ago)
- Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers (3 days ago)
- New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens (3 days ago)
- OpenAI pledges to add Astra security as Anthropic loosens Fable’s leash (4 days ago)
- US cloud ‘kill switch’ is as dangerous as ransomware, European businesses fear (4 days ago)
- New York State Department of Financial Services Secures Cybersecurity Settlement with Order Express, Inc. (4 days ago)
- City of Coweta hit with system-wide ransomware attack, has backup (4 days ago)
- Water system controllers don’t belong on the internet, says ex-NSA chief after suspected Iran attacks (4 days ago)
- Boston Children’s Hospital named in North Korean hacking operation (4 days ago)
- Ransomware attacks spike as world distracted by AI (4 days ago)
- Beware cut-price AI services that read your every word (4 days ago)
- N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands (4 days ago)
- MIT boffins’ TONTOU attack slips through Spectre defenses on Intel and AMD CPUs (4 days ago)
- Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder (4 days ago)
- AU: Hackers leak sensitive Victorian court data to dark web (4 days ago)
- What Canvas learned from a massive cyberattack (4 days ago)
- Attacker phished way into US defense supplier’s Microsoft 365 account (4 days ago)
- Exact Sciences - 10,869,543 breached accounts (4 days ago)
- Incident with Actions (4 days ago)
- What’s the Difference Between Automated Vulnerability Scanning and Penetration Testing? (5 days ago)
- Dangling DNS record for bastion.certb.cdp.bethesda.net (5 days ago)
- CL.0 desync in www.microsoft.com (5 days ago)
- CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass (PoC) (5 days ago)
- [KIS-2026-16] Telenia Software TVox <= 26.5.3 (nice) Local Privilege Escalation Vulnerability (5 days ago)
- [KIS-2026-15] Telenia Software TVox <= 26.5.3 (action_audio.php) OS Command Injection Vulnerability (5 days ago)
- [KIS-2026-14] Telenia Software TVox <= 26.5.3 (set_env.php) Authentication Bypass Vulnerability (5 days ago)
- [KIS-2026-13] vBulletin <= 6.2.1 (runMaths) Remote Code Execution Vulnerability (5 days ago)
- APPLE-SA-07-27-2026-8 Safari 26.6 (5 days ago)
- APPLE-SA-07-27-2026-7 visionOS 26.6 (5 days ago)
- APPLE-SA-07-27-2026-6 watchOS 26.6 (5 days ago)
- Canadian Man Pleads Guilty in Snowflake Extortions (5 days ago)
- Incident with Pages - Deployment Lag (5 days ago)
- Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits (5 days ago)
- Inter-Con Security - 276,114 breached accounts (6 days ago)
- Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency (6 days ago)
- Some Copilot Cloud Agent jobs not starting (6 days ago)
- Fake IRS letters target cryptocurrency holders (7 days ago)
- Incident with Copilot (8 days ago)
- Welcoming the Nepalese Government to Have I Been Pwned (8 days ago)
- Weekly Update 515 (9 days ago)
- Incident with Copilot AI Model Providers (10 days ago)
- Degraded availability GPT 5.6 Luna (10 days ago)
- SplitVPN - 865,336 breached accounts (10 days ago)
- The $5 million threat: AI Is supercharging phishing attacks (11 days ago)
- Read This Before You Buy That TV Streaming Stick (12 days ago)
- Copilot model Claude Fable 5 experiencing elevated errors (12 days ago)
- North Korea’s elite hackers turned on their own government – and got caught (12 days ago)
- Smashing Security podcast #478: This job interview could destroy your company (13 days ago)
- Incident with Copilot AI Model Providers (13 days ago)
- Incident with Actions (13 days ago)
- Houston City College - 831,642 breached accounts (14 days ago)
- PureLogs, PureRAT and misleading zgRAT (15 days ago)
- Incident with GraphQL API Requests (15 days ago)
- Weekly Update 514: This Week in Data Breaches (16 days ago)
- Actions run failures and delays (17 days ago)
- Several GPT models degraded (17 days ago)
- Incident with Actions (17 days ago)
- Incident with Pull Requests (18 days ago)
- Disruption with some GitHub services (18 days ago)
- Incident With Blocked GitHub.com Traffic (18 days ago)
- OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know (19 days ago)
- Latency issues across a number of services (19 days ago)
- Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker (20 days ago)
- Disruption with actions hosted runners (20 days ago)
- LG to Ban Residential Proxies from Smart TV Apps (21 days ago)
- Some SSH connections using deploy keys are failing (21 days ago)
- Ukraine warns fake CAPTCHAs are being used to make you hack yourself (21 days ago)
- Weekly Update 513: Clauding The Home Network (21 days ago)
- Suno - 55,282,226 breached accounts (22 days ago)
- Disruption with GPT 5.3 Codex (22 days ago)
- Incident with GitHub Actions (22 days ago)
- Disruption with some GitHub services (22 days ago)
- Paidwork - 23,272,765 breached accounts (23 days ago)
- Google’s Gemini lets strangers send messages from your locked Android phone (25 days ago)
- Anubis ransomware: what you need to know (26 days ago)
- Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers (26 days ago)
- Fluke - 821,100 breached accounts (27 days ago)
- Goose Creek - 6,574,121 breached accounts (27 days ago)
- Weekly Update 512: IoT Lockout Fail (28 days ago)
- Microsoft Patches a Record 570 Security Flaws (28 days ago)
- The ransomware negotiator who was working for the other side (28 days ago)
- Lessons Learned from CISA’s Recent GitHub Leak (29 days ago)