threat-intel Read This Before You Buy That TV Streaming Stick A security firm, Bitsight, uncovered a complex and widespread ad fraud network centered around H96 streaming devices. These devices, often sold by major retailers, are secretly used to generate revenue by masquerading as… Krebs on Security · Jul 30, 2026 High CHHOSIiotproxyad fraud
threat-intel American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials An American man is facing prosecution for wiping his GrapheneOS-powered phone before handing it over to border officials. The feature, designed to protect user data by erasing the device upon incorrect passcode entry, ha… Schneier on Security · Jul 30, 2026 Medium privacysecurityconstitution
threat-intel Timeless Compliance: Why Better Questions Beat Bigger Frameworks The article argues that the proliferation of AI frameworks and questionnaires is largely ineffective due to their tendency to generate verbose, evidence-light responses. Instead of relying on a massive collection of disp… SecurityWeek · Jul 30, 2026 Medium aicomplianceframeworks
threat-intel Claude Mythos — Hype vs. Reality: What Security Teams Need to Know The Anthropic Claude Mythos AI model has sparked significant debate and concern within the cybersecurity community. Initially touted for its ability to autonomously discover and exploit critical vulnerabilities in decade… Dark Reading · Jul 30, 2026 High CHUNaivulnerabilitycybersecurity
threat-intel Jailed Flock vandal wipes out three cameras, racks up thousands in damages This article is a collection of miscellaneous tech news items, including a report on corporate IT workloads moving off-site, a lament for Intel's Optane storage technology, a security alert about Joomla extensions being… The Register · Jul 30, 2026 Medium securitycybersecurityvulnerability
threat-intel ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories This week’s ‘ThreatsDay’ bulletin highlights a diverse range of security threats, including AI-powered hacking campaigns, ransomware attacks targeting Russia, and vulnerabilities in various software systems. Notably, a C… The Hacker News · Jul 30, 2026 High CVE-2026-33017CVE-2026-21858CVE-2025-68613RUCCHransomwaresupply chainphishing
threat-intel North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn North Korea's Lazarus Group is sharing its cyber tools and infrastructure with ransomware hackers, specifically the Gunra group, targeting South Korean organizations. The agencies warn that even visiting compromised legi… The Record · Jul 30, 2026 High SONOnorth korearansomwarelazarus group
threat-intel DataBahn Raises $40 Million for Agentic Data Pipeline Management DataBahn, a Texas-based company specializing in data pipeline management, has secured $40 million in Series B funding to bolster its agentic data control plane and expand its capabilities. This investment will allow them… SecurityWeek · Jul 30, 2026 Info data-managementdata-governanceai
threat-intel North Korean hackers behind major open-source supply chain attacks, Amazon says North Korean hackers, operating under the alias SapphireSleet, have been responsible for a series of attacks targeting widely used open-source JavaScript packages. These attacks, spanning from March 2025 to March 2026, i… The Record · Jul 30, 2026 High KRnorth koreaopen sourcesupply chain
threat-intel Discern Security Raises $13 Million in Series A Funding Discern Security, a California-based security platform company, has raised $13 million in Series A funding to bolster its AI-powered security posture evaluation and control improvement platform. The company aims to help… SecurityWeek · Jul 30, 2026 Info aisecurityposture
threat-intel Cantina Emerges From Stealth With $8 Million in Funding Cantina, a cybersecurity startup, secured $8 million in funding to bolster its agentic vulnerability management platform. The platform utilizes AI to automate vulnerability identification, prioritization, and remediation… SecurityWeek · Jul 30, 2026 Medium vulnerabilityaiautomation
threat-intel Onyx Security Raises $113 Million to Control AI Agents in the Enterprise Onyx Security, an Israeli cybersecurity firm, secured $113 million in Series B funding to address the growing security challenges associated with the increasing use of AI agents within enterprise environments. This inves… SecurityWeek · Jul 30, 2026 Medium ISaisecuritycybersecurity
threat-intel ‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale A research firm, Silent Push, demonstrated how artificial intelligence can significantly amplify the effectiveness of ‘dangling DNS takeover’ attacks, a vulnerability where a forgotten DNS record points to a deleted clou… SecurityWeek · Jul 30, 2026 High dangling dnsdns takeovercloud security
threat-intel Open Source Software: Security Principles and Practices The CISA released guidance on securing open source software (OSS) usage across various systems, including critical infrastructure. This guidance focuses on a comprehensive approach to OSS risk management, covering everyt… CISA Advisories · Jul 30, 2026 Info open sourceossvulnerability
threat-intel Cyber extortionists steal data from UK Department for Education Cybercriminals, identifying as ExfilSquad, have stolen data from the UK Department for Education and the Police National Legal Database, potentially exposing names, email addresses, and contact details of over 600,000 in… The Record · Jul 30, 2026 High UKransomwaredata breachcybercrime
threat-intel Mitsubishi Electric CC-Link IE TSN Communication Protocol A critical vulnerability (CVE-2026-13584) exists in the CC-Link IE TSN communication protocol used by Mitsubishi Electric industrial controllers. Attackers with network access can manipulate communication data by sending… CISA Advisories · Jul 30, 2026 Critical CVE-2026-13584cc-linkindustrial control systemsvulnerability
threat-intel o6 Automation open62541 Multiple vulnerabilities have been identified in o6 Automation open62541, a control system software, potentially allowing for denial of service, arbitrary code execution, and information disclosure. These vulnerabilities… CISA Advisories · Jul 30, 2026 Critical CVE-2026-63362CVE-2026-65423CVE-2026-63035vulnerabilitycontrol-systemcisa
threat-intel CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs The CISA is warning the Water and Wastewater Systems sector about a significant increase in cyberattacks targeting Programmable Logic Controllers (PLCs). Threat actors are modifying passwords to lock out operators and di… CISA Advisories · Jul 30, 2026 High plccybersecurityoperational technology
threat-intel Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents Microsoft Copilot for Word has a vulnerability that allows hidden instructions within a Word document to be copied into new documents and then re-introduced during subsequent Copilot drafting sessions. This allows an att… The Hacker News · Jul 30, 2026 High prompt injectionai securitycopilot
threat-intel Planity visée par une vente présumée de données piratées A hacker is offering a database allegedly containing information on nearly a million people linked to Planity, a platform connecting users with beauty and wellness professionals. Planity acts as an intermediary, facilita… ZATAZ · Jul 30, 2026 Medium data breachphishingdata leak