2026-07-27
Amazon Security
AWS Shield Advanced is embracing the AWS WAF Anti-DDoS managed rule group: What changes and how to prepare
Malwarebytes
Aftercall ads are driving Android users crazy
MIT Technology Review
OpenAI called the Hugging Face attack unprecedented. But we’ve been here before.
Step Security
2026 Mid-Year Update: On Pace for Our Biggest Year Yet
Artem Golubin
Writing arenas in Rust from scratch
Microsoft Security
Rethinking security for the age of AI
Microsoft Security
Enhancing AI security through global AI red teaming
Amazon Security
Announcing the Cloud Security Alliance on AWS Compliance Guide
Ars Technica Security
Activist charged with felony after giving border agent "duress code" that wiped his phone
Exodus Blog
From Virtual Share to Physical Shell: Leveraging Windows’ Inconsistent Access Control for LPE
MIT Technology Review
How lasers could help provide fuel for nuclear reactors
Cloudflare
We’re open-sourcing our privacy proxy CLI
MIT Technology Review
The Download: lasers for nuclear fuel, and organ preservation advances
MIT Technology Review
The path to artificial superintelligence
MIT Technology Review
Closing the data loop in AI-driven drug discovery
MIT Technology Review
Building the enterprise environment for agentic AI
Schneier on Security
Cognyte Sells a Mobile Cell Surveillance Van
Malwarebytes
A week in security (July 20 – July 26)
ISC SANS
ISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024, (Mon, Jul 27th)
Elastic Security Labs
Inside Elastic InfoSec's agentic SOC: How we cut AI agent LLM calls by 60%
Star Labs
When AI Makes 0-Days Feel Like N-Days
2026-07-25
Step Security
Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials
Joshua Rogers
33 Vulnerabilities in cJSON
2026-07-24
Dark Reading
CISOs vs. Boards: Myth or Misunderstanding?
Schneier on Security
Friday Squid Blogging: Illex Squid Catch in the Falklands
MIT Technology Review
The quest to keep organs alive outside the body
Malwarebytes
Don’t get fooled by TikTok resin art scams
Malwarebytes
Google wants to store a selfie video of your face
MIT Technology Review
The Download: an organ transplant breakthrough, and homegrown Chinese chips
Schneier on Security
Why AI Needs a “Genie Coefficient”
Escape DAST
AI pentesting, Mission log: July
ISC SANS
ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)
Teleport Blog
VPN Alternative for Internal Web Apps | Teleport
Elastic Security Labs
Inside Elastic InfoSec's agentic SOC: When to inline your agent's skills for a 5× cost reduction
2026-07-23
Cloudflare
Introducing Cache Response Rules
Talos Intelligence
Don’t swing at everything
MIT Technology Review
Supercooled kidneys have been transplanted into pigs in a “landmark achievement”
Amazon Security
Enterprise security at machine speed: AWS Black Hat 2026 preview
Github Security Blog
The case for a cooldown: Why Dependabot now waits before issuing version updates
Microsoft Security
Email threat landscape: Q2 2026 trends and insights
MIT Technology Review
The Download: energy transmission and US threats against Chinese AI
CISA Alerts & Advisories
MZ Automation libIEC61850
CISA Alerts & Advisories
Panduit IntraVUE
CISA Alerts & Advisories
Weintek cMT3092X
CISA Alerts & Advisories
Rockwell Automation ThinManager
CISA Alerts & Advisories
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
CISA Alerts & Advisories
Johnson Controls XAAP Android
CISA Alerts & Advisories
Johnson Controls C-CURE 9000 and Victor application server
CISA Alerts & Advisories
MZ Automation lib60870
Rapid7
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
Schneier on Security
End-to-End Encryption and “Going Dark”
Offensive Security
The EU AI Act Deadline Is Approaching. Is Your Workforce Ready?
Talos Intelligence
Preview: Cisco Talos at Black Hat USA 2026
Google Safety & Security
Introducing selfie for sign-in: a new, easy way to access your Google Account
Hunt and Hackett
Attackers do not need to break in, they simply log in
TrustedSec
CCPA Update: Who’s In Scope (Part 1)
Step Security
Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization
Datadog HQ
Provision Datadog on Stripe Projects
Elastic Security Labs
wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution
Elastic Security Labs
How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts
2026-07-22
Zero Salarium
PE OopsSec: Mind your PE, guard your OPSEC
Mend
199 RubyGems, two techniques, zero working payloads: Inside a cryptomining campaign that never ran
Dark Reading
Attackers Are Learning to Live Off the AI Toolchain
Ars Technica Security
OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face
Github Security Blog
Next chapter: Restructuring GitHub’s bug bounty program
Artem Golubin
Domain registration information should be transparent
Aikido
SQL injection isn't dead
NVISO Labs
Intercepting Android WebView traffic under new certificate validity requirement by Chromium
Black Hills Info Sec
The Life of a SOC Analyst: Responsibilities, Challenges, and Strategies for Success
Searchlight Cyber
Preemptive Threat Exposure Management: Frequently Asked Questions
Eclypsium
Announcing InfraTrust, the source of intelligence on security risks across hardware infrastructure
Searchlight Cyber
July 21st – This Week’s Top Cybersecurity and Dark Web Stories
CISA Alerts & Advisories
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Schneier on Security
First-Person Identity Theft Story
Krebs on Security
LG to Ban Residential Proxies from Smart TV Apps
2026-07-21
Aikido
Tyro's CISO: Being the "Einstein of cybersecurity" isn't enough if developers don't trust you
Black Lantern Security
CVE-2026-12118 - IBM webMethods Integration Server: Pre-Auth RCE via WmServiceMock
Zero Day Initiative
Pwn2Own Ireland 2026 – New Targets and Categories
Héber Júlio
OSCP — The Good, Very Good, and the Bad
Amazon Security
Do more with AWS WAF labels using dynamic label interpolation
Bishop Fox Security
A Millisecond of Predictability: Why CVE-2026-11374 Is Hard to Exploit
Ars Technica Security
Apps targeted at US troops contain Chinese and Russian code
CISA Alerts & Advisories
Rockwell Automation 1718-AENTR/1719-AENTR
CISA Alerts & Advisories
Rockwell Automation Studio 5000 Logix Designer
CISA Alerts & Advisories
Siemens Opcenter X
CISA Alerts & Advisories
Tycon Systems TPDIN-Monitor-WEB2
CISA Alerts & Advisories
Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
CISA Alerts & Advisories
Siemens IAM Client
CISA Alerts & Advisories
Rockwell Automation 1734 POINT I/O
CISA Alerts & Advisories
Rockwell Automation FactoryTalk Services Platform
CISA Alerts & Advisories
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA Alerts & Advisories
Siemens SIDIS Secured SmartPlug
CISA Alerts & Advisories
Siemens CADRA
Schneier on Security
MIT to Become Hotbed of AI Video Surveillance
Escape DAST
wp2shell (CVE-2026-63030 + CVE-2026-60137): WordPress pre-auth RCE, now detected by Escape
Sicuranext Blog
Patching WP2Shell in the dark using PAI
Sicuranext Blog
Patching WP2Shell in the dark using PAI
Compass Security Blog
The Hidden Privilege of Automation Platforms
ISC SANS
ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)
Teleport Blog
Identity Security for AI
2026-07-20
Filippo Valsorda
Opaque, Interoperable Passkey Records (and a Go API)
Amazon Security
Introducing the Amazon GuardDuty investigation agent: on-demand AI-powered threat assessment