2026-07-31
Elastic Security Labs
Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend
2026-07-30
Ars Technica Security
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Dark Reading
AI Harnesses Burst With Potential Exploit Opps
Talos Intelligence
You were onto something with “It’s the Climb,” Miley
Amazon Security
Extend Amazon Inspector SBOM Generator with Plugins
MIT Technology Review
Montana’s plan to become an experimental medical hub just pushed forward
Krebs on Security
Read This Before You Buy That TV Streaming Stick
Schneier on Security
American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials
Embrace The Red
Escaping Linux Sandboxes via PipeWire (CVE-2026-5674)
Microsoft Security
What’s new in Microsoft Security: July 2026
Zero Day Initiative
The July 2026 Apple Security Update Review
MIT Technology Review
The Download: tricking LLMs, and reviving geothermal plants
CISA Alerts & Advisories
Open Source Software: Security Principles and Practices
CISA Alerts & Advisories
MZ Automation GmbH libiec61850
CISA Alerts & Advisories
MikroTik RouterOS
CISA Alerts & Advisories
Schneider Electric IGSS
CISA Alerts & Advisories
Mitsubishi Electric CC-Link IE TSN Communication Protocol
CISA Alerts & Advisories
Toptech Systems RCU II+ and Multiload II+
CISA Alerts & Advisories
Watchfire Controller Software
CISA Alerts & Advisories
NASA Core Flight System (cFS) Health & Safety (HS) Application
CISA Alerts & Advisories
Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
CISA Alerts & Advisories
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
CISA Alerts & Advisories
MZ Automation lib60870
CISA Alerts & Advisories
Johnson Controls OpenBlue Employee
CISA Alerts & Advisories
o6 Automation open62541
Schneier on Security
Should You Use AI for a Task? Here’s a Simple Way to Decide
Trail of Bits
Building secure Uniswap v4 hooks
MIT Technology Review
A fundamental flaw leaves LLMs strikingly vulnerable to attack
Talos Intelligence
Black Hat special: Rewind and revisit
2026-07-29
Ars Technica Security
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
MIT Technology Review
How an overlooked geothermal plant got a second chance
Dark Reading
Hugging Face Hack: Lessons for Cyber Defenders
Schneier on Security
Measuring the Tendency of AI Agents to Go Rogue
Microsoft Security
Better security starts with better questions
Github Security Blog
Tame Dependabot: Group your updates, slow the cadence, keep security fast
Ars Technica Security
Anthropic is finding bugs faster than Microsoft can fix them
Malwarebytes
AI robocalls: Why caller ID is still lying to you
Amazon Security
Secure your npm and pip package updates in Amazon Linux
Black Hills Info Sec
Report As You Go: Maintaining Good Documentation for SOC Analysts
Aikido
Top SAST tools 2026
Searchlight Cyber
July 28th – This Week’s Top Cybersecurity and Dark Web Stories
MIT Technology Review
The Download: a chip talent battle, and deflating AI hype
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Alerts & Advisories
2026 Minimum Elements for a Software Bill of Materials (SBOM)
Schneier on Security
Long-Lived Vulnerability in Microsoft Secure Boot
MIT Technology Review
The AI Hype Index: Unsexy AI
Step Security
Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan
Schneier on Security
Measuring LLMs’ Ability to Perform Cryptanalysis
Datadog HQ
A practical guide to React error monitoring
Elastic Security Labs
Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here
2026-07-28
Step Security
2026 Mid-Year Update: On Pace for Our Biggest Year Yet
Ars Technica Security
We now have a better understanding how OpenAI hacked into Hugging Face
Palo Alto Networks
Palo Alto Networks Achieves Global CBPR and PRP Certifications
Github Security Blog
Disrupting supply chain attacks on npm and GitHub Actions
Cloudflare
Natural disasters and government interference: examining Q2 2026’s major Internet disruption events
Malwarebytes
Shared Claude chats were searchable on Google
MIT Technology Review
The Download: OpenAI’s predictable hack, and an AI stock sell-off
Eye Security Research
AI-powered Phishing-as-a-Service: Inside Two BEC Kits
CISA Alerts & Advisories
CI Fortify – Advice for isolating vital systems
CISA Alerts & Advisories
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
CISA Alerts & Advisories
ABB KNX Update Tool
CISA Alerts & Advisories
igloohome Smart Lock Mobile Application
CISA Alerts & Advisories
MikroTik RouterOS and Cloud Hosted Router
CISA Alerts & Advisories
Siemens Mendix Runtime
CISA Alerts & Advisories
Siemens Desigo CC
CISA Alerts & Advisories
Siemens SIMATIC S7-PLCSIM Advanced
Schneier on Security
Axon Is Another License Plate Surveillance Company
Trail of Bits
How we use /goal to find bugs in Patch the Planet
Talos Intelligence
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
MIT Technology Review
Samsung’s chip workers are jumping ship to rival SK Hynix
TrustedSec
AI Directives and AI Strategy Development
ISC SANS
ISC Stormcast For Tuesday, July 28th, 2026 https://isc.sans.edu/podcastdetail/10026, (Tue, Jul 28th)
Snyk
The Generator Can't Be the Validator: What OpenAI's Hugging Face Incident Proves About AI Security
Rosecurify
Seclog - #188
Adepts of 0xCC
From your doorbell to your home network
2026-07-27
Ars Technica Security
Microsoft unveils AI security tools it says outperform competing platforms
Dark Reading
Agentic Browsers Rewind Web Security by 20 Years
Amazon Security
AWS Shield Advanced is embracing the AWS WAF Anti-DDoS managed rule group: What changes and how to prepare
Malwarebytes
Aftercall ads are driving Android users crazy
Dark Reading
Why Resetting Passwords No Longer Stops Attackers
MIT Technology Review
OpenAI called the Hugging Face attack unprecedented. But we’ve been here before.
Artem Golubin
Writing arenas in Rust from scratch
Microsoft Security
Rethinking security for the age of AI
Microsoft Security
Enhancing AI security through global AI red teaming
Amazon Security
Announcing the Cloud Security Alliance on AWS Compliance Guide
Ars Technica Security
Activist charged with felony after giving border agent "duress code" that wiped his phone
Exodus Blog
From Virtual Share to Physical Shell: Leveraging Windows’ Inconsistent Access Control for LPE
MIT Technology Review
How lasers could help provide fuel for nuclear reactors
Cloudflare
We’re open-sourcing our privacy proxy CLI
CISA Alerts & Advisories
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Schneier on Security
Cognyte Sells a Mobile Cell Surveillance Van
Malwarebytes
A week in security (July 20 – July 26)
ISC SANS
ISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024, (Mon, Jul 27th)
Elastic Security Labs
Inside Elastic InfoSec's agentic SOC: How we cut AI agent LLM calls by 60%
Star Labs
When AI Makes 0-Days Feel Like N-Days
2026-07-25
XPN's Blog
Jailbreaking Local Models with JSON
Step Security
Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials
Joshua Rogers
33 Vulnerabilities in cJSON
2026-07-24
Dark Reading
CISOs vs. Boards: Myth or Misunderstanding?
Schneier on Security
Friday Squid Blogging: Illex Squid Catch in the Falklands
Malwarebytes
Don’t get fooled by TikTok resin art scams
Malwarebytes
Google wants to store a selfie video of your face
Schneier on Security
Why AI Needs a “Genie Coefficient”
Escape DAST
AI pentesting, Mission log: July
ISC SANS
ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)
Elastic Security Labs
Inside Elastic InfoSec's agentic SOC: When to inline your agent's skills for a 5× cost reduction
Teleport Blog
VPN Alternative for Internal Web Apps | Teleport