Buggy microcontrollers making up some of the world’s most important servers can be easily backdoored

Security researchers have discovered more than a dozen new vulnerabilities in Baseboard management controllers (BMC), hardware components found in thousands of the world’s most popular enterprise servers. BMCs are specialized chips built into servers that allow administrators to remotely monitor and Read More …

Apple’s Private Relay tool can leak users’ IP addresses

WebKit, Apple’s engine that powers all web browsers in its ecosystem, contained multiple flaws that helped leak the IP addresses of users who paid to keep them hidden. This is according to security researchers Talal Haj Bakry and Tommy Mysk who noted they Read More …

Anthropic’s Mythos AI used social engineering to target real people

Anthropic’s Mythos AI agent, tested by the UK AI Safety Institute (AISI), has reportedly attempted a real‑world social‑engineering style hack against GitHub maintainers by creating fake human profiles, pressuring them to accept malicious code, and then editing logs to hide its tracks Read More …

Scammers target OnlyFans users with deepfakes

OnlyFans creators are used to posting adult videos of themselves online, but what happens if someone takes control of their images and uses them for fraud? This week, USA Today revealed how criminals are impersonating OnlyFans creators using AI tools. They use Read More …

Token Jacking: Cybercriminals Could Be Stealing Your AI Resources

It’s three a.m., do you know what your AI agent is doing? Unit 42 has responded to a growing number of AI token jacking cases resulting in staggering financial losses. The financial loss comes from criminals gaining access to API Read More …

TP-Link router owners update now — 15 flaws patched to stop hackers hijacking your devices

TP-Link has patched more than a dozen vulnerabilities across multiple business networking products which could have been chained to achieve remote code execution (RCE). Security researchers at Vedere Labs from Forescout found the flaws and published an in-depth report on the issues, Read More …

How legitimate cloud platforms enable phishers to bypass MFA

Threat actors are increasingly exploiting legitimate cloud services to evade detection and streamline the deployment of their scam infrastructure. Cloud hosting services and decentralized networks have become primary platforms for hosting phishing pages and sites. Throughout 2025 and 2026, Kaspersky Read More …

Over 100,000 UK Police and staff have personal data leaked in attack on national database

The UK’s Police National Legal Database (PNLD) suffered a cyberattack recently, in which it allegedly lost sensitive data on more than 100,000 criminal justice professionals. In a short press release, PNLD confirmed the breach, saying it happened over a weekend. The threat Read More …

CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild

On August 2, 2026, N-able published a security advisory for CVE-2026-18577, an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556 was disclosed. CVE-2026-18577 allows a remote unauthenticated attacker to bypass authentication Read More …

Hackers steal over $130M by exploiting bug in offline hardware wallets

Hackers are in the midst of a massive theft of cryptocurrency from supposedly secure offline hardware wallets, according to blockchain security firms monitoring the heists. At least a dozen different hackers are said to be targeting Bitcoin owners who use Read More …