threat-intel Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default Several security-related stories are emerging, including a focus on AI security and vulnerabilities, a Russian phishing campaign mimicking Signal support, and ongoing efforts to improve security across various Linux and… The Register · Aug 8, 2026 Medium RUIRaisecurityphishing
threat-intel New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens Researchers at PortSwigger have discovered several new attack vectors targeting webmail interfaces, allowing attackers to steal passwords, take over accounts, and manipulate AI tools. The vulnerabilities exploit weakness… The Hacker News · Aug 8, 2026 High webmailcsshtml
threat-intel OpenAI pledges to add Astra security as Anthropic loosens Fable's leash OpenAI is bolstering its AI security by integrating Astra, while Anthropic is loosening restrictions on its Fable system. This shift reflects growing concerns about the potential risks associated with increasingly autono… The Register · Aug 7, 2026 Medium IRaisecurityvulnerability
threat-intel Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks An ex-NSA chief is warning that water system controllers, which are increasingly connected to the internet, are vulnerable to attacks, particularly from Iran. He believes these devices represent a significant security ri… The Register · Aug 7, 2026 Medium IRcybersecurityinfrastructureiran
threat-intel Ransomware attacks spike as world distracted by AI Ransomware attacks are increasing, potentially coinciding with a global focus on AI. This article highlights a range of security incidents, including a zero-day exploit targeting on-prem SharePoint, phishing attacks mimi… The Register · Aug 7, 2026 Medium IRransomwarephishingvulnerability
vulnerability MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs This article discusses a vulnerability related to Spectre defenses on Intel and AMD CPUs, where an AI-powered attack, dubbed TONTOU, successfully bypassed existing security measures. The vulnerability stems from AI's str… The Register · Aug 7, 2026 Medium CHIRspectrevulnerabilityai
data-breach Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder A Scottish NHS trust is investigating a security breach that may have exposed the medical records of a 9-year-old girl. This follows the arrest of a man on suspicion of murder, and authorities are examining how unauthori… The Register · Aug 7, 2026 High UKvulnerabilitysharepointhealthcare
threat-intel Growing Up The Hard Way This article explores the evolving landscape of open source software and the increasing need for commercial support to ensure its long-term viability. The author argues that open source is transitioning into a two-tiered… The Hacker News · Aug 7, 2026 High open sourcemaintenancevendor
threat-intel Attacker phished way into US defense supplier's Microsoft 365 account A US defense supplier's Microsoft 365 account was compromised after an attacker successfully phished credentials. The attacker exploited a vulnerability to gain access, highlighting a continuing issue with phishing attac… The Register · Aug 7, 2026 Medium phishingmicrosoftcredential theft
threat-intel Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails A widespread phishing campaign, leveraging adversary-in-the-middle (AitM) techniques and residential proxies, is targeting organizations across various sectors in the U.S., Canada, and Europe. The campaign, linked to the… The Hacker News · Aug 7, 2026 High USCAEUaitmphishingmicrosoft 365
threat-intel 'Asimov was right' about rules for robots, says ex-US Cyber Director This article highlights a range of cybersecurity and technology news, including a Microsoft SharePoint vulnerability exploited in the wild, a Russian phishing campaign mimicking Signal support, and acquisitions within th… The Register · Aug 7, 2026 Medium RUvulnerabilityphishingacquisition
vulnerability Microsoft, Apple Release Fresh Security Updates Microsoft and Apple released a combined set of security updates addressing dozens of vulnerabilities across their products, including critical remote code execution flaws. These updates target a wide range of products, i… SecurityWeek · Aug 7, 2026 Critical CVE-2026-63508CVE-2026-56162CVE-2026-65667vulnerabilityremote code executionpatch
threat-intel Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access Researchers have discovered a vulnerability in Windows Hello for Business that allows malware running within a signed-in session to leverage the victim's hardware-backed authentication key to gain persistent access to Mi… The Hacker News · Aug 7, 2026 High windowsentria idwebauthn
threat-intel China launches mysterious probe into security of Palo Alto Networks' products Chinese authorities are investigating the security of Palo Alto Networks' products, raising concerns about potential vulnerabilities and a broader effort to monitor and control cybersecurity technology within China. This… The Register · Aug 7, 2026 Medium CNcybersecuritychinapalo alto
threat-intel How the famed USENIX Security conf is managing a flood of papers in the AI era The USENIX Security conference is grappling with a surge in research papers, particularly those leveraging AI and machine learning. While AI usage is increasing, concerns are being raised about the potential for autonomo… The Register · Aug 6, 2026 Medium USCHRUaimachine learningvulnerability
threat-intel AI struggles to patch vulns without adult supervision AI systems are struggling to independently patch vulnerabilities in software without human oversight, leading to incomplete remediation and potential security risks. The article highlights instances where AI-driven patc… The Register · Aug 6, 2026 Medium aimachine learningvulnerability patching
threat-intel IT department put sticky notes on the laptops to help employees log in This article is a collection of security-related news snippets from The Register. It covers a range of topics including a phishing campaign mimicking Signal support, a zero-day exploit targeting on-prem SharePoint, and a… The Register · Aug 6, 2026 Medium CHIRSWphishingzero-dayransomware
threat-intel AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory A new attack vector, dubbed "AI Recommendation Poisoning," is spreading across websites, leveraging "Ask AI" buttons to silently manipulate Large Language Model (LLM) memory. Attackers embed hidden prompts within these b… The Hacker News · Aug 6, 2026 High prompt injectionllmmemory poisoning
threat-intel Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison Maksim Silnikau, the mastermind behind the Ransom Cartel ransomware operation, has been sentenced to 16 years in prison for his role in a multi-year criminal scheme targeting organizations across the US and abroad. The o… SecurityWeek · Aug 6, 2026 High BEUKRUransomwarecybercrimeextradition
threat-intel Prompt injection isn't the bug, AI agent frameworks are This article discusses the increasing risk of prompt injection attacks within AI agent frameworks, rather than the models themselves. The rise of open-source AI models, particularly from China, is prompting a reaction fr… The Register · Aug 5, 2026 Medium CHIRUSprompt injectionaillm