Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself post, augustus 5, 2026augustus 17, 2026 An agent running Anthropic’s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK’s AI Security Institute. When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch… Continue Reading
Russia State-Sponsored Hackers Turn Hotel and Conference Wi-Fi Networks Into Malware Delivery Systems post, augustus 4, 2026augustus 17, 2026 Russian state backed hackers are compromising public Wi-Fi infrastructure at hotels, conference centres and other shared venues to intercept travellers’ internet traffic, distribute remote-access malware and steal access to corporate cloud accounts, according to new research from Microsoft. The campaign, which Microsoft calls CaptiveCrunch, has been attributed to Storm-2945, an… Continue Reading
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests post, augustus 4, 2026augustus 17, 2026 OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people outside the intended testing boundaries. These incidents are unrelated to the previously disclosed Hugging Face breach, in which OpenAI… Continue Reading
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root post, augustus 4, 2026augustus 17, 2026 cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database’s root context, crossing the privilege boundary between a cPanel account and the server’s administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The database bug… Continue Reading
New DOUBLECUP ClickFix service hides malware in browser cache images post, augustus 3, 2026augustus 17, 2026 A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. SOCRadar’s Threat Research Unit says DOUBLECUP has operated since early June… Continue Reading
ExfilSquad hackers leak info of over 100,000 UK police officers, staff post, augustus 3, 2026augustus 17, 2026 A cyberattack on the U.K.’s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. The intrusion was detected on Sunday, July 26, and was later claimed by the ExfilSquad data extortion group, which alleges it stole 135,000 contact records…. Continue Reading
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware post, juli 31, 2026augustus 17, 2026 Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is… Continue Reading
Amgen says cloud data breach exposed patient health, proprietary info post, juli 31, 2026augustus 17, 2026 Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. Amgen is a California-based biotechnology company that develops and manufactures medicines for serious illnesses, including cancer, cardiovascular disease, inflammation, and rare diseases…. Continue Reading
AI-systeem Claude van Anthropic hackte onbedoeld drie bedrijven post, juli 31, 2026 Het bekende AI-systeem Claude van het Amerikaanse bedrijf Anthropic heeft ingebroken bij drie bedrijven, nadat het onbedoeld toegang had gekregen tot het internet. Dat heeft Anthropic bekendgemaakt, een week nadat iets soortgelijks was gemeld door concurrent OpenAI. Volgens Anthropic hebben de hacks ergens sinds april plaatsgevonden, tijdens zogeheten ‘capture-the-flag’-oefeningen. Daarbij kreeg Claude… Continue Reading
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs post, juli 30, 2026juli 31, 2026 CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat… Continue Reading