Search the Portal

Recent Articles

JUL31
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range of apps and use-cases that it wasn't originally

The Hacker News by info@thehackernews.com (The Hacker News)
JUL31
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session. The operator, tracked through the aliases knaithe and KnYuan,

The Hacker News by info@thehackernews.com (The Hacker News)
JUL31
Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace

The internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase. The post Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace appeared first on SecurityWeek.

Security Week by Ionut Arghire
JUL31
EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels

When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI. The post EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels appeared first on SecurityWeek.

Security Week by Associated Press
JUL31
Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations

A security company’s systems were hacked after it installed a malicious Python package deployed by Claude. The post Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations appeared first on SecurityWeek.

Security Week by Eduard Kovacs
JUL31
Critical Flaw Led to Azure Cosmos DB Pwnage

Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access. The post Critical Flaw Led to Azure Cosmos DB Pwnage appeared first on SecurityWeek.

Security Week by Ionut Arghire
JUL31
CareCloud Data Breach Impacts Over 350,000

In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment. The post CareCloud Data Breach Impacts Over 350,000 appeared first on SecurityWeek.

Security Week by Ionut Arghire
JUL31
Critical Code Execution Vulnerability Patched in TeamCity 

Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol. The post Critical Code Execution Vulnerability Patched in TeamCity appeared first on SecurityWeek.

Security Week by Ionut Arghire
JUL31
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without its knowledge. The AI firm said the earliest incidents date back to April 2026, adding it made the discoveries after launching a "

The Hacker News by info@thehackernews.com (The Hacker News)
JUL30
CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems. The post CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs appeared first on SecurityWeek.

Security Week by Mike Lennon
JUL30
Bank of America to Acquire Cybersecurity Firm MDSec

The acquisition will add approximately 65 cybersecurity professionals to Bank of America’s operations in the United Kingdom. The post Bank of America to Acquire Cybersecurity Firm MDSec appeared first on SecurityWeek.

Security Week by SecurityWeek News
JUL30
Okta to Acquire Identity Threat Detection Firm Permiso

The deal extends Okta's reach beyond identity management and into the realm of security operations, positioning the company to compete more directly on identity threat detection and response. The post Okta to Acquire Identity Threat Detection Firm Permiso appeared first on SecurityWeek.

Security Week by SecurityWeek News
JUL30
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is that bogus macOS software update screen stealthily

The Hacker News by info@thehackernews.com (The Hacker News)
JUL30
Read This Before You Buy That TV Streaming Stick

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a...

Krebs on Security by BrianKrebs
JUL30
Timeless Compliance: Why Better Questions Beat Bigger Frameworks

The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. The post Timeless Compliance: Why Better Questions Beat Bigger Frameworks appeared first on SecurityWeek.

Security Week by Matt Honea