2026-08-04
Elastic Security Labs
Benchmarking the Agentic SOC: How we evaluate LLMs for security workflows
Schneier on Security
Iran Cyberattacks Against Minnesota Water Systems
Microsoft Security
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
The Citizen Lab
A Roadmap for Confronting the Chilling Effects of Censorship, Surveillance and New Technology
Microsoft Security
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
SentinelOne
From Input to Impact: Secure AI Where It Runs
Palo Alto Networks
Redefining Network Security for the Frontier AI Era
Cloudflare
Introducing: Cloudflare Agents
Escape DAST
Escape joins Anthropic’s Cyber Verification Program to advance AI-powered offensive security
MIT Technology Review
The Download: US robot restrictions, and ICE’s DNA grab
CISA Alerts & Advisories
Thermo Fisher Applied Biosystems Genetic Analyzers
CISA Alerts & Advisories
Acrisure KARR BT and DR-100
CISA Alerts & Advisories
CISA Adds Three Known Exploited Vulnerabilities to Catalog
Socket
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Schneier on Security
Some Claude Chats Are Searchable on Google
Talos Intelligence
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI
Eye Security
The Real Cost of Ransomware in 2026
Compass Security Blog
Pipeleek v1 Release
TrustedSec
TLS Encryption and Compliance
ISC SANS
ISC Stormcast For Tuesday, August 4th, 2026 https://isc.sans.edu/podcastdetail/10036, (Tue, Aug 4th)
Elastic Security Labs
Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human
2026-08-03
Malwarebytes
“Adult TikTok” searches lead to scams
Dark Reading
New Tool Traces AI Videos Back to Their Source
MIT Technology Review
Trump’s AI protectionism has come for robotics
Schneier on Security
More on the OpenAI Agent’s Attack on Hugging Face
Project Discovery
Watching Agents Work: A Behavioral Audit of Offensive-Security LLM Runs
Talos Intelligence
[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents
Embrace The Red
LLM Heist: Hijacking LiteLLM for Traffic Interception, Key Theft, and Tool-Call Injection
Palo Alto Networks
Introducing Unit 42 Threat Intelligence: Know What Matters, Understand the Adversary, and Act Faster
Rapid7
Metasploit Pro 5.1 Released
Dark Reading
Is There Really a Fix for CISO Fatigue?
MIT Technology Review
The Download: reward hacking explained, and suspected Iranian cyberattacks
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
Escape DAST
Escape joins OpenAI’s Trusted Access for Cyber (TAC) to advance AI-powered offensive security
Schneier on Security
The OpenAI Hack Shows the Genie Is Out of the Bottle
RME-DisCo Research Group
Bringing Structure to Memory Forensics: A Five-Phase, MITRE ATT&CK-Aligned Workflow
MIT Technology Review
Here’s why AI agents lie and cheat to reach their goals
Rapid7
Rapid7 Expands UK and Ireland Channel Presence Through Strategic Partnership with Exclusive Networks
Malwarebytes
A week in security (July 27 – August 2)
Step Security
Anthropic Incident: An AI Agent Published a Malicious Package to PyPI and 15 Real Systems Ran It
ISC SANS
ISC Stormcast For Monday, August 3rd, 2026 https://isc.sans.edu/podcastdetail/10034, (Mon, Aug 3rd)
Troy Hunt
Weekly Update 515
Elastic Security Labs
SOC case management and detection rule history in Elastic Security
2026-08-01
Ars Technica Security
Defcon's new badge is a security key you can see inside
Rosecurify
Seclog - #189
2026-07-31
Elastic Security Labs
Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas
Schneier on Security
Friday Squid Blogging: Squid Helps Discover New Marine Species
Microsoft Security
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Ars Technica Security
Claude published malicious code to the Internet and attacked 3 real companies
Amazon Security
HIPAA Security Rule on AWS – Technical Safeguards Implementation and Readiness Guidance
The Citizen Lab
Kate Robertson on the Risks That Lie Behind Canada’s Unexpected Signing of the UN Cybercrime Convention
Schneier on Security
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
Ars Technica Security
AI scammers outperform humans when it comes to building trust
Bishop Fox Security
What Security Leaders Think About Frontier AI Models: Firsthand of Mythos
MIT Technology Review
The Download: Montana’s new experimental drug rules
Schneier on Security
Facial Recognition at Madison Square Garden
Malwarebytes
Fake Flash Player installs AtlasRAT
MIT Technology Review
Montana’s new “right to try” law can’t come soon enough for some
Dark Navy
Patch In, Exploit Out: How deepsec Reconstructed the Pwn2Own Microsoft Edge Sandbox Escape
ISC SANS
ISC Stormcast For Friday, July 31st, 2026 https://isc.sans.edu/podcastdetail/10032, (Fri, Jul 31st)
Elastic Security Labs
What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support
Elastic Security Labs
Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend
Elastic Security Labs
Alert Zero: AI-driven alert triage and attack investigation for the agentic SOC
2026-07-30
Ars Technica Security
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Step Security
Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan
Dark Reading
AI Harnesses Burst With Potential Exploit Opps
Talos Intelligence
You were onto something with “It’s the Climb,” Miley
Amazon Security
Extend Amazon Inspector SBOM Generator with Plugins
MIT Technology Review
Montana’s plan to become an experimental medical hub just pushed forward
Krebs on Security
Read This Before You Buy That TV Streaming Stick
Schneier on Security
American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials
Microsoft Security
What’s new in Microsoft Security: July 2026
Embrace The Red
Escaping Linux Sandboxes via PipeWire (CVE-2026-5674)
Zero Day Initiative
The July 2026 Apple Security Update Review
MIT Technology Review
The Download: tricking LLMs, and reviving geothermal plants
CISA Alerts & Advisories
Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
CISA Alerts & Advisories
Schneider Electric IGSS
CISA Alerts & Advisories
Johnson Controls OpenBlue Employee
CISA Alerts & Advisories
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
CISA Alerts & Advisories
NASA Core Flight System (cFS) Health & Safety (HS) Application
CISA Alerts & Advisories
o6 Automation open62541
CISA Alerts & Advisories
MZ Automation lib60870
CISA Alerts & Advisories
Open Source Software: Security Principles and Practices
CISA Alerts & Advisories
MZ Automation GmbH libiec61850
CISA Alerts & Advisories
Mitsubishi Electric CC-Link IE TSN Communication Protocol
CISA Alerts & Advisories
MikroTik RouterOS
CISA Alerts & Advisories
Toptech Systems RCU II+ and Multiload II+
CISA Alerts & Advisories
Watchfire Controller Software
Schneier on Security
Should You Use AI for a Task? Here’s a Simple Way to Decide
Trail of Bits
Building secure Uniswap v4 hooks
MIT Technology Review
A fundamental flaw leaves LLMs strikingly vulnerable to attack
Talos Intelligence
Black Hat special: Rewind and revisit
2026-07-29
Dark Reading
Cybersecurity, Then & Now
Ars Technica Security
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
MIT Technology Review
How an overlooked geothermal plant got a second chance
Dark Reading
Hugging Face Hack: Lessons for Cyber Defenders
Schneier on Security
Measuring the Tendency of AI Agents to Go Rogue
Github Security Blog
Tame Dependabot: Group your updates, slow the cadence, keep security fast
Microsoft Security
Better security starts with better questions
Ars Technica Security
Anthropic is finding bugs faster than Microsoft can fix them
Malwarebytes
AI robocalls: Why caller ID is still lying to you
Amazon Security
Secure your npm and pip package updates in Amazon Linux
Aikido
Top SAST tools 2026
Searchlight Cyber
July 28th – This Week’s Top Cybersecurity and Dark Web Stories
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Alerts & Advisories
2026 Minimum Elements for a Software Bill of Materials (SBOM)
Datadog HQ
A practical guide to React error monitoring
Elastic Security Labs
Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here
2026-07-28
Step Security
2026 Mid-Year Update: On Pace for Our Biggest Year Yet
Ars Technica Security
We now have a better understanding how OpenAI hacked into Hugging Face