ICYMI: 2026-08-04
Latest Headlines
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted
Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
Landmark Deal Would Officially Add Laser Weapons to US Army Arsenal
Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)
Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer
CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout
Weaponized Email AI Assistants Could Help Attackers Hijack Accounts
TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover
Obsidian Security Raises $85 Million at $1.1 Billion Valuation
Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering
Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
New XCSSET variant targets macOS devs via compromised Xcode projects
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Varonis Agent IBAC keeps AI agents within their intended boundaries
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
– MTZ