threat-intel Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Apple has finally fixed a significant security flaw in its Hide My Email service, which allowed real email addresses to be exposed in mail logs. The issue stemmed from sending a rejected spam email to a Hide My Email use… The Hacker News · Jul 21, 2026 Medium privacysecurityicloud
threat-intel Captive Portal Detection, (Tue, Jul 21st) This article details how operating systems and browsers detect captive portals – the splash screens that appear when connecting to public Wi-Fi networks. Instead of intercepting old non-TLS homepages, these systems now… SANS Internet Storm Center · Jul 21, 2026 Medium captive portalwifinetwork detection
threat-intel India says allegedly leaked nuclear plant files pose no safety risk A cybercrime group, World Leaks (formerly Hunters International ransomware), has allegedly leaked thousands of files related to India's Kudankulam Nuclear Power Plant, claiming they originated from a breach involving Rel… The Record · Jul 20, 2026 High INcybercrimedata breachnuclear
threat-intel Senator calls on Rubio, Blanche to push back against Canadian surveillance legislation Senator Ron Wyden is urging the Trump administration to push back against Canadian legislation that could force U.S. tech companies to create backdoors and share user data, potentially compromising U.S. national security… The Record · Jul 16, 2026 High CAUSsurveillanceprivacyencryption
threat-intel New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password A new macOS infostealer, dubbed ClickLock Stealer, is actively targeting users by forcing them to enter their passwords repeatedly through a loop of killing apps. The malware, a copy of GSocket, uses a deceptive Cloudfla… The Hacker News · Jul 16, 2026 High EUmacosinfostealerpassword
threat-intel AI Data Centers and the Concentration of Wealth This article argues that focusing solely on opposition to AI data centers in the US is a misguided approach, as it obscures the larger issue of corporate AI dominance and the concentration of wealth within the industry.… Schneier on Security · Jul 13, 2026 High CHUNaidata centerscorporate power
threat-intel More Countries Jump on the Social Media Ban Wagon More countries are implementing social media bans for minors, driven by concerns about mental health and safety. However, companies are struggling to comply while minimizing user disruption and avoiding intrusive data co… Dark Reading · Jul 10, 2026 Medium AUUNsocial mediaage verificationprivacy
threat-intel Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself A 15-year-old in Japan used an AI chatbot to automatically cancel nearly 47,000 anime streaming subscriptions within hours. Simultaneously, researchers have documented the first fully autonomous, agentic AI-driven ransom… Graham Cluley · Jul 8, 2026 High JPairansomwarecyberattack
policy Supreme Court allows Texas app law requiring age verification to take effect The Supreme Court has allowed a Texas law requiring age verification for apps to take effect while a lower court considers its constitutionality. This law mandates that app developers and stores use age verification tool… The Record · Jul 7, 2026 Info USprivacyregulationfirst amendment
threat-intel European Parliament Member Investigating Spyware Was Hacked With Pegasus A report by Citizen Lab revealed that former European Parliament member Stelios Kouloglou was repeatedly hacked with the Pegasus spyware while investigating the use of commercial surveillance tools, including Pegasus. Th… The Hacker News · Jul 3, 2026 High UKGRRUspywarepegasusapple
malware PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords PamStealer, a new macOS information stealer developed by Jamf Threat Labs, utilizes deceptive tactics like mimicking the Maccy clipboard manager and exploiting Pluggable Authentication Modules (PAM) to steal login creden… The Hacker News · Jul 3, 2026 High RUBYKZmacosstealercredential theft
threat-intel Spyware found on phone of European Parliament member probing it A former European Parliament member, Stelios Kouloglou, was repeatedly targeted with Pegasus spyware while investigating the misuse of commercial spyware. Citizen Lab researchers discovered the infections occurred during… The Record · Jul 3, 2026 High GRDERUspywarepegasuseuropean parliament
threat-intel Apple Reverses Age-Old Patch Policy to Keep Up With AI Apple is shifting its security patching strategy to a more frequent, independent release model in response to the accelerating pace of AI-driven attacks. Historically, Apple bundled security updates with major OS release… Dark Reading · Jul 2, 2026 High USaizero-daypatching
threat-intel ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories This week’s security news highlights several vulnerabilities and ongoing threats across various sectors. A phishing campaign targeting small businesses globally with ransomware, a root escape vulnerability in Claude Cowo… The Hacker News · Jul 2, 2026 High CVE-2026-33825CHUNGEphishingransomwaresandbox
threat-intel Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them. This article reports on a significant investment by IBM and Red Hat into Project Lightwell, a new service designed to address the growing challenge of securing open-source software supply chains. Driven by Anthropic's My… Dark Reading · Jul 2, 2026 High USaivulnerabilityopen source
threat-intel And the Winner in Dominant Malware Delivery? ClickFix ClickFix, a social engineering technique where attackers trick users into executing malicious commands via error messages, has become the dominant method for malware delivery, according to a recent ReliaQuest analysis. T… Dark Reading · Jul 1, 2026 High USsocial engineeringmalware deliveryobfuscation
threat-intel House passes kids’ online safety bill, but Senate approval unlikely The House of Representatives passed the Kids Internet and Digital Safety (KIDS) Act, aiming to bolster online safety for children, but the bill faced criticism for lacking key provisions like a ‘duty of care’ and strong… The Record · Jun 30, 2026 Medium USonline safetychildrenprivacy
vulnerability AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks Researchers have identified six security flaws in AirDrop and Quick Share, wireless file-sharing features used on Apple and Samsung devices. These vulnerabilities allow an attacker within range to trigger crashes, bypass… The Hacker News · Jun 30, 2026 High CVE-2024-38271CVE-2024-38272CVE-2024-10668USGBairdropquicksharecrash
threat-intel Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs Apple released a significant security update addressing over 30 vulnerabilities across its iOS, macOS, and Safari platforms. Notably, several WebKit vulnerabilities were identified using AI tools, highlighting a new tren… The Hacker News · Jun 30, 2026 Medium CVE-2026-43707CVE-2026-43716CVE-2026-43745webkitaivulnerability
threat-intel Justices rule that cellphone location histories are protected by the Fourth Amendment The Supreme Court ruled that police use of cellphone location history data obtained from tech companies constitutes a Fourth Amendment search and requires a warrant. This decision effectively rejects the "third-party doc… The Record · Jun 29, 2026 High USfourth amendmentlocation trackingprivacy