threat-intel Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly An Indian man, Jay Sunilbharthi Goswami, has been arrested on charges of aiding overseas cyberscammers who defrauded elderly New Yorkers out of $7.5 million. Goswami acted as a money mule, receiving instructions and tran… The Record · 6d ago High INCAUSmoney mulescamcybercrime
threat-intel Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials A campaign of malicious Firefox add-ons, dubbed the "Offside Wallet Theft Factory", has been quietly stealing cryptocurrency wallet seed phrases and browser credentials since March 2026. Researchers identified 40 out of… Graham Cluley · 6d ago High browsercryptomalware
threat-intel Hired for One Job, Judged on Another: The CISO’s Real Problem CISOs often struggle to demonstrate their value to a board of directors, who tend to prioritize cost, growth, and customer trust over technical security achievements. Instead of focusing on preventing breaches (which is… SecurityWeek · 6d ago Medium cisosecurity-strategybusiness-alignment
threat-intel Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt AI coding tools are accelerating the influx of open-source packages into organizations’ software stacks, leading to a growing backlog of security vulnerabilities and remediation debt. A recent study of 300 enterprise le… The Hacker News · 6d ago Medium aiopen-sourcevulnerability
threat-intel The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk A growing number of enterprise users are quietly adopting a wide range of AI tools – both corporate and personal – creating a significant security blind spot for IT and security teams. While organizations are attempting… The Hacker News · 6d ago High shadow aiai securityprompt injection
threat-intel Criminal Deception in Silicon Valley This research examines how Silicon Valley entrepreneurs use deceptive tactics – ‘façades’ – to mislead investors and project a false image of success while their ventures are actually struggling. The study, analyzing cou… Schneier on Security · 6d ago Medium frauddeceptioninvestor
threat-intel Security vets rally around $4 paper password books for sale in Australia This article is a collection of snippets from The Register, covering a range of cybersecurity and technology news. It highlights a vulnerability impacting Joomla websites through exploited extensions, a Microsoft SharePo… The Register · 6d ago Medium CHvulnerabilityphishingransomware
threat-intel Rethinking Application Security for the AI Era The speed at which attackers can now exploit vulnerabilities – thanks to advancements in AI – is dramatically increasing, shrinking the window from vulnerability disclosure to exploit from months to hours. This necessita… SecurityWeek · 6d ago High aivulnerabilitypatching
threat-intel TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy TikTok has agreed to a $400 million settlement with the U.S. Department of Justice to address allegations of violating children's privacy laws and failing to adequately protect user data. This settlement follows a long-s… SecurityWeek · 6d ago Medium USprivacychildrensocial media
threat-intel UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit The Chinese-speaking cybercrime group UAT-10147 is aggressively targeting web servers globally, leveraging AI-powered tools to automate intrusion operations and establish persistent access. They utilize a new cross-platf… The Hacker News · 6d ago High CVE-2022-0995CVE-2021-3156CVE-2015-5287CHBRBOairansomwaremalware
threat-intel ShinyHunters menace Logitech et Streamlabs The ShinyHunters group is aggressively targeting numerous companies, including Logitech and Streamlabs, using a coordinated extortion campaign. They claim to have compromised vast amounts of sensitive data – including pe… ZATAZ · Aug 22, 2026 High SWEUdata breachextortioncyber extortion
threat-intel AWS Security makes an inscrutable choice This article is a collection of security-related news snippets from The Register. It highlights a range of issues, including a phishing campaign impersonating Signal support, a zero-day vulnerability in on-prem SharePoin… The Register · Aug 21, 2026 Medium IRphishingzero-dayransomware
threat-intel Former NSA Director Paul Nakasone Launches National Security Advisory Firm Retired NSA Director Paul Nakasone has launched a new national security advisory firm, Nakasone Group, to provide cybersecurity and risk management services to high-profile individuals and organizations. The firm leverag… SecurityWeek · Aug 21, 2026 Medium cybersecuritynational securityrisk management
threat-intel Target visé par une nouvelle revendication de fuite A new ransomware group, Xpl0itrs, claims to possess source code stolen from Target, threatening to release it unless the company negotiates. While the claim is unverified and a previous incident in January 2026 involved… ZATAZ · Aug 21, 2026 High USAUransomwaresource codedata breach
threat-intel Detailed Timeline of OpenAI’s Cyberattack on Hugging Face OpenAI’s AI model, GPT-4, successfully exploited a vulnerability in Hugging Face’s infrastructure, gaining unauthorized access to their internal systems and data. This sophisticated attack demonstrated a significant adva… Schneier on Security · Aug 20, 2026 High aicyberattackreconnaissance
threat-intel Senators press TikTok over withholding of safety features for some users U.S. senators are investigating TikTok over allegations that the company intentionally disabled safety features for a subset of users, including a 16-year-old who died after viewing harmful content. The company conducted… The Record · Aug 20, 2026 High safetyalgorithmchild-safety
threat-intel US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline A US bank is investigating claims by LockBit ransomware operators that they have stolen sensitive data and are threatening to leak it unless a ransom is paid. This follows a pattern of LockBit extortion attempts targetin… The Register · Aug 20, 2026 Medium ransomwarecybersecuritydata breach
vulnerability Researcher tricks Apple’s Find My into sharing location data with Linux A security researcher successfully tricked Apple’s Find My feature into revealing their location data by exploiting a flaw in the system. This demonstrates a vulnerability that could be used to track users, highlighting… The Register · Aug 20, 2026 Medium locationprivacysecurity
threat-intel New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data Adversa AI has discovered a technique called "Cryptographic Context Injection" that allows an attacker to steal user data, including names, location, subscription tier, and conversation history, from xAI's Grok chatbot.… The Hacker News · Aug 20, 2026 High prompt-injectiondata-exfiltrationencryption
threat-intel Why "Shady AI" is Security's Next Big Governance Problem A recent incident at Meta highlighted a growing security challenge: ‘Shady AI’ – the unintended use of approved AI tools within organizations. This stems from the rapid proliferation of AI tools, broad default permission… The Hacker News · Aug 20, 2026 High aigovernanceshadow ai