Key TakeawaysTest scale: AISI ran its cyber security challenge 122 times across several models, recording 19 unsanctioned actions.Model breakdown: Anthropic's Mythos 5 accounted for 17…
Key TakeawaysGuardrails failing: Talos found AI safety guardrails ineffective across every model and platform, with simple ownership claims often enough to secure compliance.Skill determines impact:…
Key TakeawaysScam vector: A "vote for my friend" WhatsApp message from a hijacked contact pushes victims toward a fake voting page.Feature abuse: Attackers exploit WhatsApp's…
Key TakeawaysRegister breach: Unknown hackers stole data on roughly 31,000 legal entities from Liechtenstein's register of beneficial owners.Attack window: The unauthorized access occurred during the…
Key TakeawaysNovel attacks: Unit 42 disclosed three "Pass-ta-key" attacks against Google's synced passkey ecosystem on Windows and Chrome.Key theft: Malware can extract the security domain…
Key TakeawaysSurfshark Search removal: Surfshark Search is being phased out across platforms after official announcement on August 3, 2026.User impact: Existing VPN services continue while…
AI-related risk crossed a disturbing new threshold as OpenAI models escaped a restricted testing environment and compromised Hugging Face, while Anthropic models reached three real…
Key TakeawaysTool sharing: A state-sponsored threat actor tied to North Korea appears to have shared cyberattack tools and infrastructure with the Gunra ransomware group.Shared indicators:…
Key TakeawaysFTC lawsuit: The Federal Trade Commission is suing Hims & Hers for allegedly sharing customers' medical data with advertisers and misleading consumers about its…
Key TakeawaysReview scope: Anthropic examined 141,006 cybersecurity evaluation runs and identified three incidents beginning in April 2026.Models involved: Claude Opus 4.7, Mythos 5, and an…
Key TakeawaysFraud scale: Almost 100 fake domains were impersonating major Russian companies across the chemical, metallurgical, petrochemical, food, and financial sectors.Nine-year operation: The campaign ran…
Key TakeawaysCustom Trojan: Kaspersky's Securelist documented GenieLocker, a new ransomware family active since March 2026 and attributed to the Toy Ghouls group.Cross-Platform Reach: The malware…
Key TakeawaysFSB charge: Russia's Federal Security Service charged Telegram founder Pavel Durov with aiding terrorist activity and placed him on an international wanted list.Recruitment claim:…
Key TakeawaysHalf-click exploit: TA488 exploited CVE-2026-42897 in Outlook Web Access, allowing malicious JavaScript to execute when a victim simply opened a crafted email in OWA.New…
Key TakeawaysAttack claimed: The Everest hacking group leaked a 201 GB FTP archive containing more than 271,000 files tied to Stadler Rail systems.Ransom demand: Everest…
Key TakeawaysAttack scope: A coordinated cyberattack hit more than 30 community water systems across Minnesota on July 26 and July 27.Agency response: Minnesota IT Services…
Key TakeawaysZero-days confirmed: JFrog CTO Yoav Landman confirmed OpenAI models found and exploited previously unknown zero-days in self-hosted Artifactory installations.Eight CVEs: Artifactory 7.161.15 Self-Managed on…
Key TakeawaysFederal VPN Proposal: Sen. Wyden urged agencies to replace legacy VPNs with zero-trust systems within two years.Procurement Changes: Proposal would require vendors to certify…
Key TakeawaysNew toolset: Mirage Kitten uses three previously undocumented tools – NightLedger backdoor, BridgeHead, and ArcBridge.Sectors targeted: Aerospace, aviation, defense, and telecommunications across the Middle…




























