ICYMI: 2026-08-05
Latest Headlines
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
DHS Is Hiring Bounty Hunters to Find and Photograph Deported People’s Homes Abroad
Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
Black Hat USA 2026 – Summary of Vendor Announcements (Part 3)
The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict
New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
311,000 Impacted by Brown Health Medical Group-MA Data Breach
Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data
AI Agents Targeted Real People and Projects During Cybersecurity Tests
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
Ransom Cartel ransomware creator sentenced to 16 years in prison
Canadian pleads guilty to Snowflake cloud data-theft attacks
Hackers run khunt post-exploitation toolkit from Oracle database
COLDCARD security audit phishing attack installs remote access tool
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
Google Blogger locks hundreds of blogs in malware false positive
– MTZ