2026-08-06
Talos Intelligence
Why metaphor may dictate your security strategy
Offensive Security
Why “AI Pentesting” is the Wrong Term (And Why We Need AI Red Teaming)
Krebs on Security
Canadian Man Pleads Guilty in Snowflake Extortions
Github Security Blog
How we took malware advisories beyond npm
Amazon Security
Caching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scale
Cloudflare
Give any website a WebMCP interface
Cloudflare
The next generation of MCP
Cloudflare
Introducing Kitesurf: The agent-first browser that runs in V8 isolates on Cloudflare Workers
MIT Technology Review
The Download: Google’s AI shake-up and Meta’s rogue model
CISA Alerts & Advisories
ABB Ability Zenon
CISA Alerts & Advisories
Johnson Controls Inc. TL280
CISA Alerts & Advisories
Medixant RadiAnt DICOM
Malwarebytes
Scammers target OnlyFans users with deepfakes
Schneier on Security
Adversarial Clothing Designed to Fool Facial Recognition Systems
TrustedSec
The Art of Hunting Azure Cloud Secrets
Elastic Security Labs
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
2026-08-05
Dark Reading
AI Sends Global Crime Syndicates Into Fraud Nirvana
Ars Technica Security
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Dark Reading
No Perfect Fix for AI Browser Prompt Injection Flaws
Amazon Security
AWS partners with Anthropic and OpenAI to bring AWS Continuum into developer workflows
Ars Technica Security
Anthropic’s AI used fake identities, malware in rogue attack on GitHub project
Dark Reading
CSS: The Hidden Threat Lurking in Your Inbox
Meta Security
From User Sequences to Scaling Laws: A Multi-Stage Architecture for Meta’s Ads Ranking
Socket
UK Cyber Test: AI Agent Attempted to Social Engineer Open Source Maintainer Into Merging Malware
Amazon Security
From 2 weeks to 2 minutes: Amazon Cognito launches Provisioned limits for self-service rate limit management
Palo Alto Networks
Prisma AIRS - Unified Data Protection for Claude
Microsoft Security
Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
MIT Technology Review
Puzzle Corner
The Citizen Lab
Immigration Policy: The Backdoor to Transnational Repression
Cloudflare
The Agent Access Model
MIT Technology Review
The Download: NASA’s new telescope and Chinese tech import curbs
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
Trail of Bits
A few notes on AWS Nitro Enclaves: KMS integration
Schneier on Security
Vulnerabilities in Car Anti-Theft Device
Malwarebytes
Junk Cleaner clears the clutter from your Android
Searchlight Cyber
August 4th – This Week’s Top Cybersecurity and Dark Web Stories
MIT Technology Review
NASA’s new dark-energy space telescope can also detect killer asteroids
Dark Reading
Angola's Largest Telco Breached Hours Before IPO
Dark Navy
DoGNAVY CyberGym Technical Report
Datadog HQ
This Month in Datadog - July 2026
2026-08-04
Elastic Security Labs
Benchmarking the Agentic SOC: How we evaluate LLMs for security workflows
Microsoft Security
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
Schneier on Security
Iran Cyberattacks Against Minnesota Water Systems
Microsoft Security
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
The Citizen Lab
A Roadmap for Confronting the Chilling Effects of Censorship, Surveillance and New Technology
Microsoft Security
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
SentinelOne
From Input to Impact: Secure AI Where It Runs
Palo Alto Networks
Redefining Network Security for the Frontier AI Era
Cloudflare
Introducing: Cloudflare Agents
Escape DAST
Escape joins Anthropic’s Cyber Verification Program to advance AI-powered offensive security
MIT Technology Review
The Download: US robot restrictions and ICE’s DNA grab
CISA Alerts & Advisories
Thermo Fisher Applied Biosystems Genetic Analyzers
CISA Alerts & Advisories
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA Alerts & Advisories
Acrisure KARR BT and DR-100
Socket
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Schneier on Security
Some Claude Chats Are Searchable on Google
Talos Intelligence
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI
Compass Security Blog
Pipeleek v1 Release
TrustedSec
TLS Encryption and Compliance
ISC SANS
ISC Stormcast For Tuesday, August 4th, 2026 https://isc.sans.edu/podcastdetail/10036, (Tue, Aug 4th)
Elastic Security Labs
Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human
2026-08-03
Malwarebytes
“Adult TikTok” searches lead to scams
Dark Reading
New Tool Traces AI Videos Back to Their Source
MIT Technology Review
Trump’s AI protectionism has come for robotics
Schneier on Security
More on the OpenAI Agent’s Attack on Hugging Face
Project Discovery
Watching Agents Work: A Behavioral Audit of Offensive-Security LLM Runs
Talos Intelligence
[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents
Embrace The Red
LLM Heist: Hijacking LiteLLM for Traffic Interception, Key Theft, and Tool-Call Injection
Palo Alto Networks
Introducing Unit 42 Threat Intelligence: Know What Matters, Understand the Adversary, and Act Faster
Rapid7
Metasploit Pro 5.1 Released
Dark Reading
Is There Really a Fix for CISO Fatigue?
MIT Technology Review
The Download: reward hacking explained and suspected Iranian cyberattacks
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
Escape DAST
Escape joins OpenAI’s Trusted Access for Cyber (TAC) to advance AI-powered offensive security
Schneier on Security
The OpenAI Hack Shows the Genie Is Out of the Bottle
RME-DisCo Research Group
Bringing Structure to Memory Forensics: A Five-Phase, MITRE ATT&CK-Aligned Workflow
MIT Technology Review
Here’s why AI agents lie and cheat to reach their goals
Rapid7
Rapid7 Expands UK and Ireland Channel Presence Through Strategic Partnership with Exclusive Networks
Malwarebytes
A week in security (July 27 – August 2)
Step Security
Anthropic Incident: An AI Agent Published a Malicious Package to PyPI and 15 Real Systems Ran It
ISC SANS
ISC Stormcast For Monday, August 3rd, 2026 https://isc.sans.edu/podcastdetail/10034, (Mon, Aug 3rd)
Troy Hunt
Weekly Update 515
Elastic Security Labs
SOC case management and detection rule history in Elastic Security
2026-08-01
Ars Technica Security
Defcon's new badge is a security key you can see inside
Rosecurify
Seclog - #189
2026-07-31
Elastic Security Labs
Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas
Schneier on Security
Friday Squid Blogging: Squid Helps Discover New Marine Species
Microsoft Security
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Ars Technica Security
Claude published malicious code to the Internet and attacked 3 real companies
Amazon Security
HIPAA Security Rule on AWS – Technical Safeguards Implementation and Readiness Guidance
The Citizen Lab
Kate Robertson on the Risks That Lie Behind Canada’s Unexpected Signing of the UN Cybercrime Convention
Schneier on Security
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
Malwarebytes
Fake Fortnite rewards are stealing players’ accounts
Ars Technica Security
AI scammers outperform humans when it comes to building trust
Bishop Fox Security
What Security Leaders Think About Frontier AI Models: Firsthand of Mythos
MIT Technology Review
The Download: Montana’s new experimental drug rules
Schneier on Security
Facial Recognition at Madison Square Garden
Malwarebytes
Fake Flash Player installs AtlasRAT
MIT Technology Review
Montana’s new “right to try” law can’t come soon enough for some
Dark Navy
Patch In, Exploit Out: How deepsec Reconstructed the Pwn2Own Microsoft Edge Sandbox Escape
Elastic Security Labs
What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support
Elastic Security Labs
Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend
Elastic Security Labs
Alert Zero: AI-driven alert triage and attack investigation for the agentic SOC
2026-07-30
Ars Technica Security
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Step Security
Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan