SecOps News

Get this as an RSS feed

  • Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse (13 minutes ago)
  • DeadLock ransomware uses blockchain to resist infrastructure takedown (3 hours ago)
  • Signal adds an extra layer of security to make sure you’re actually chatting with the right person (3 hours ago)
  • 421 bugs in Microsoft’s Patch Tuesday release, and the Norks have already attacked one (3 hours ago)
  • Microsoft Plugs Nearly 400 Security Holes (4 hours ago)
  • Sandworm hackers target IT pros with trojanized WireGuard VPN client (4 hours ago)
  • Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack (5 hours ago)
  • Incident with GraphQL API Requests (5 hours ago)
  • Cisco warns of ASA and FTD VPN flaw exploited to crash devices (5 hours ago)
  • Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing (5 hours ago)
  • Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client (6 hours ago)
  • August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day (6 hours ago)
  • Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands (6 hours ago)
  • Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees (6 hours ago)
  • Microsoft releases Windows 10 KB5120249 extended security update (7 hours ago)
  • Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days (7 hours ago)
  • Windows 11 KB5121003 & KB5120240 cumulative updates released (7 hours ago)
  • Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws (8 hours ago)
  • Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE (8 hours ago)
  • DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt (8 hours ago)
  • DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi (9 hours ago)
  • Wesco confirms security incident after ExfilSquad claims data theft (9 hours ago)
  • Zoom Patches Zero-Click Code Execution Vulnerability (9 hours ago)
  • Two wars and a World Cup lead to epic DDoS attacks on publishers (9 hours ago)
  • The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It (10 hours ago)
  • Device Bound Session Credentials lands in Chrome on macOS (11 hours ago)
  • SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities (11 hours ago)
  • US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ (11 hours ago)
  • Mozilla updates GPG signing key for Firefox releases after exposure (12 hours ago)
  • Vague Task, Total Access: When AI Delegation Becomes a Security Risk (12 hours ago)
  • OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development (12 hours ago)
  • DDoS attacks over 1 Tbps surged fivefold in the second quarter (12 hours ago)
  • Deepfake hiccup unmasks suspected digital certificate fraudster (13 hours ago)
  • CISA: Microsoft SharePoint flaw now exploited in ransomware attacks (13 hours ago)
  • A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices (13 hours ago)
  • Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo (13 hours ago)
  • Corma Raises $60 Million for Defensive Cybersecurity AI Model (13 hours ago)
  • Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub (13 hours ago)
  • Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers (13 hours ago)
  • Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities (14 hours ago)
  • Cisco warns of high-severity ClamAV flaws with public exploits (14 hours ago)
  • Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11 (14 hours ago)
  • Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets (15 hours ago)
  • GRC Solutions Partners with Defense.com™ to Help Businesses Take Control of Cyber Risk (15 hours ago)
  • Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption (15 hours ago)
  • US and South Korea warn of Gunra ransomware targeting govt agencies (15 hours ago)
  • OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber (15 hours ago)
  • Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G (15 hours ago)
  • Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks (16 hours ago)
  • Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine (18 hours ago)
  • BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins (19 hours ago)
  • Disruption with Copilot for access to some models (1 days ago)
  • DEF CON hackers add new muscle to water utility protection (1 days ago)
  • Disruption with creation of fine grained personal access tokens (1 days ago)
  • Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development (1 days ago)
  • North Korean spies are running local LLMs to cause AI mischief (1 days ago)
  • Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list (1 days ago)
  • China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw (1 days ago)
  • Everything I Learned Shipping Device Bound Session Credentials (1 days ago)
  • ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors (1 days ago)
  • Attackers pick Levi’s pockets in social engineering attack (1 days ago)
  • Wetherspoons bars smart glasses from filming customers (1 days ago)
  • Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development (1 days ago)
  • New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA (1 days ago)
  • Cyber vulnerability sweep picks up Royal Navy drones sending data to China (1 days ago)
  • TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore (1 days ago)
  • Framework loses customer data in Metabase zero-day attack (1 days ago)
  • Claude Code puts auto mode in the driver’s seat (1 days ago)
  • Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials (1 days ago)
  • OpenAI’s Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause (1 days ago)
  • Advertisers are trying to influence AI bots with secret ads (1 days ago)
  • KR: 3Pro TV Data Breach Exposes 460,000 Records, Including 2,979 Bank Accounts (2 days ago)
  • Ransomware gangs skip the CEO, head straight for the 40-something IT manager (2 days ago)
  • Alcon - 218,395 breached accounts (2 days ago)
  • Ransomware gangs skip the CEO, head straight for the 40-something IT manager (2 days ago)
  • City of Suisun declares local emergency after cyberattack downs 911 dispatch system (3 days ago)
  • Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default (3 days ago)
  • City of Coweta refuses to pay ransom after system-wide cyberattack (3 days ago)
  • Brinks Home - 732,162 breached accounts (3 days ago)
  • Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers (3 days ago)
  • New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens (3 days ago)
  • OpenAI pledges to add Astra security as Anthropic loosens Fable’s leash (4 days ago)
  • US cloud ‘kill switch’ is as dangerous as ransomware, European businesses fear (4 days ago)
  • New York State Department of Financial Services Secures Cybersecurity Settlement with Order Express, Inc. (4 days ago)
  • City of Coweta hit with system-wide ransomware attack, has backup (4 days ago)
  • Water system controllers don’t belong on the internet, says ex-NSA chief after suspected Iran attacks (4 days ago)
  • Boston Children’s Hospital named in North Korean hacking operation (4 days ago)
  • Ransomware attacks spike as world distracted by AI (4 days ago)
  • Beware cut-price AI services that read your every word (4 days ago)
  • N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands (4 days ago)
  • MIT boffins’ TONTOU attack slips through Spectre defenses on Intel and AMD CPUs (4 days ago)
  • Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder (4 days ago)
  • AU: Hackers leak sensitive Victorian court data to dark web (4 days ago)
  • What Canvas learned from a massive cyberattack (4 days ago)
  • Attacker phished way into US defense supplier’s Microsoft 365 account (4 days ago)
  • Exact Sciences - 10,869,543 breached accounts (4 days ago)
  • Incident with Actions (4 days ago)
  • What’s the Difference Between Automated Vulnerability Scanning and Penetration Testing? (5 days ago)
  • Dangling DNS record for bastion.certb.cdp.bethesda.net (5 days ago)
  • CL.0 desync in www.microsoft.com (5 days ago)
  • CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass (PoC) (5 days ago)
  • [KIS-2026-16] Telenia Software TVox <= 26.5.3 (nice) Local Privilege Escalation Vulnerability (5 days ago)
  • [KIS-2026-15] Telenia Software TVox <= 26.5.3 (action_audio.php) OS Command Injection Vulnerability (5 days ago)
  • [KIS-2026-14] Telenia Software TVox <= 26.5.3 (set_env.php) Authentication Bypass Vulnerability (5 days ago)
  • [KIS-2026-13] vBulletin <= 6.2.1 (runMaths) Remote Code Execution Vulnerability (5 days ago)
  • APPLE-SA-07-27-2026-8 Safari 26.6 (5 days ago)
  • APPLE-SA-07-27-2026-7 visionOS 26.6 (5 days ago)
  • APPLE-SA-07-27-2026-6 watchOS 26.6 (5 days ago)
  • Canadian Man Pleads Guilty in Snowflake Extortions (5 days ago)
  • Incident with Pages - Deployment Lag (5 days ago)
  • Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits (5 days ago)
  • Inter-Con Security - 276,114 breached accounts (6 days ago)
  • Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency (6 days ago)
  • Some Copilot Cloud Agent jobs not starting (6 days ago)
  • Fake IRS letters target cryptocurrency holders (7 days ago)
  • Incident with Copilot (8 days ago)
  • Welcoming the Nepalese Government to Have I Been Pwned (8 days ago)
  • Weekly Update 515 (9 days ago)
  • Incident with Copilot AI Model Providers (10 days ago)
  • Degraded availability GPT 5.6 Luna (10 days ago)
  • SplitVPN - 865,336 breached accounts (10 days ago)
  • The $5 million threat: AI Is supercharging phishing attacks (11 days ago)
  • Read This Before You Buy That TV Streaming Stick (12 days ago)
  • Copilot model Claude Fable 5 experiencing elevated errors (12 days ago)
  • North Korea’s elite hackers turned on their own government – and got caught (12 days ago)
  • Smashing Security podcast #478: This job interview could destroy your company (13 days ago)
  • Incident with Copilot AI Model Providers (13 days ago)
  • Incident with Actions (13 days ago)
  • Houston City College - 831,642 breached accounts (14 days ago)
  • PureLogs, PureRAT and misleading zgRAT (15 days ago)
  • Incident with GraphQL API Requests (15 days ago)
  • Weekly Update 514: This Week in Data Breaches (16 days ago)
  • Actions run failures and delays (17 days ago)
  • Several GPT models degraded (17 days ago)
  • Incident with Actions (17 days ago)
  • Incident with Pull Requests (18 days ago)
  • Disruption with some GitHub services (18 days ago)
  • Incident With Blocked GitHub.com Traffic (18 days ago)
  • OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know (19 days ago)
  • Latency issues across a number of services (19 days ago)
  • Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker (20 days ago)
  • Disruption with actions hosted runners (20 days ago)
  • LG to Ban Residential Proxies from Smart TV Apps (21 days ago)
  • Some SSH connections using deploy keys are failing (21 days ago)
  • Ukraine warns fake CAPTCHAs are being used to make you hack yourself (21 days ago)
  • Weekly Update 513: Clauding The Home Network (21 days ago)
  • Suno - 55,282,226 breached accounts (22 days ago)
  • Disruption with GPT 5.3 Codex (22 days ago)
  • Incident with GitHub Actions (22 days ago)
  • Disruption with some GitHub services (22 days ago)
  • Paidwork - 23,272,765 breached accounts (23 days ago)
  • Google’s Gemini lets strangers send messages from your locked Android phone (25 days ago)
  • Anubis ransomware: what you need to know (26 days ago)
  • Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers (26 days ago)
  • Fluke - 821,100 breached accounts (27 days ago)
  • Goose Creek - 6,574,121 breached accounts (27 days ago)
  • Weekly Update 512: IoT Lockout Fail (28 days ago)
  • Microsoft Patches a Record 570 Security Flaws (28 days ago)
  • The ransomware negotiator who was working for the other side (28 days ago)
  • Lessons Learned from CISA’s Recent GitHub Leak (29 days ago)