An AI-generated GitHub Actions bug in Snowflake’s .NET connector was autonomously exploited by Wiz’s AI agent and swiftly patched after internal Jira access.
New Mirai-derived Linux botnet Evooo1Bot hijacks routers and edge devices as encrypted SOCKS5 relays, adding exploit modules and credential theft beyond DDoS.
A new ShieldBreak zero-day in Microsoft Defender bypasses July’s RoguePlanet patch, enabling local attackers to gain SYSTEM privileges while no fix exists yet.
Security experts warn that misconfigured Model Context Protocol servers can leak secrets via configs, overbroad access and prompt injection, urging stricter controls[1][13].
Apple is expanding its threat notifications with lock screen and settings alerts for iPhone users targeted by mercenary spyware, and urges fast action.
Jamf Threat Labs uncovered AmnesiaStealer, a multi-stage Rust macOS infostealer delivered via ClickFix that hijacks browser sessions and steals credentials.
RingCentral faces a July 2026 breach tied to ShinyHunters, with personal data for about 1.6M customer accounts exposed in a pay-or-leak extortion campaign.
Beacon CRM says a compromised AWS access key allowed attackers to copy database backups for around 1,500 UK charities, exposing donor and service user records.
A new Trump directive lets vetted US firms support government-led offensive cyber operations against transnational crime, sparking legal and escalation concerns.
New Android malware chain WindRelay plus SpyNote turns NFC phones into live card relays, letting fraudsters take out loans and transactions in real time.