Feeds last updated @: UTC - 20:45 - 29/07/2026
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
https://www.theregister.com/security
https://www.theregister.com/security/2026/07/29/word-worm-crawls-into-copilot-spreads-chaos/5280588
https://www.theregister.com/ai-and-ml/2026/07/29/mcp-gets-an-enterprise-makeover/5280027
https://hackread.com/authentication-ux-deserves-attention-b2b-platforms/
https://hackread.com/rufroot-vulnerability-attackers-hijack-ruflo-login/
https://hackread.com/ipmi-flaw-exposes-servers-offline-password-cracking/
https://hackread.com/mate-security-grows-q3-2025-pushes-past-50m-funding/
https://www.debian.org/security/
https://msrc.microsoft.com/update-guide/vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-13037
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-13032
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-13030
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-13028
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50422
https://www.ncsc.nl/expertblogs/ai-legt-de-vinger-op-de-kwetsbare-plek
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2573
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2572
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2571
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2570
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2569
https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html
https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html
https://thehackernews.com/2026/07/coordinated-cyberattack-targets-30.html
https://thehackernews.com/2026/07/nine-year-fraud-campaign.html
https://techrepublic.com/topic/security
Microsoft is retiring its legacy Threat Intelligence portal on August 1. Security teams should verify licenses, permissions, investigation projects, APIs, and automated workflows before the cutoff.
The post Microsoft Threat Intelligence Portal Retires August 1: 4 Checks Before the Cutoff appeared first on TechRepublic.
https://www.techrepublic.com/article/news-microsoft-threat-intelligence-retirement/
AI security tools are helping uncover more software flaws, creating new patching demands and potential offensive risks for enterprise IT teams.
The post More Than 45,000 Software Flaws Reported as AI Reshapes Cybersecurity appeared first on TechRepublic.
https://www.techrepublic.com/article/news-ai-software-vulnerability-surge-cybersecurity-risks/
Apple’s latest iPhone, iPad and Mac updates patch 194 unique security flaws involving root access, kernel code execution and protected data.
The post Apple Fixes 194 Security Flaws Across iPhone, Mac and Other Devices appeared first on TechRepublic.
https://www.techrepublic.com/article/news-apple-security-updates-194-vulnerabilities/
Cursor has patched a high-severity Windows vulnerability that allowed malicious Git repositories to execute code, highlighting security risks in AI coding environments.
The post Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay appeared first on TechRepublic.
https://www.techrepublic.com/article/news-cursor-git-code-execution-vulnerability-cve-2026-63093/
Coca-Cola has confirmed data was stolen in the ransomware attack on Fairlife after the Anubis gang published allegedly stolen files, escalating the incident.
The post Coca-Cola Confirms Data Theft as Fairlife Ransomware Attack Escalates appeared first on TechRepublic.
https://www.techrepublic.com/article/news-coca-cola-confirms-data-theft-fairlife-ransomware/
https://www.bleepingcomputer.com/
https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/
https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/
https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/
https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/
https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/
The Origin Energy breach down here in Aus is all over the news this week, and as with many breaches, it's multi-faceted. You've got them leading with "don't worry, your credit card is fine", the hacker leading with "they didn&
I reckon this week's video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is - if ever there was an actual value proposition for AI it's taking lots of noise and
"Build a smart home", they said. "It'll make life so much better", they said. Well, life wasn't very bloody good at 23:00 the other night after travelling 33 hours from Paris only to find the IoT doorlock batteries dead and the
How's this for a location?! I mean, last week was nice with Scott in Mallorca, but Marrakech is, well, wow 😮 Anyway, about those data breaches... This week I'm talking about the futility of attempting to remove piss from a pool, yet here we are, with
I can't recall if someone else originally came up with this saying or if I said it in some off-the-cuff comment and it just propagated, but since it's often attributed back to me, I'll relay it here regardless:
Trying to delete yourselfhttps://www.troyhunt.com/swimming-pools-pee-and-trying-to-delete-your-data-from-the-internet/
This essay was written with Barath Raghavan, and originally appeared in The Guardian.
In July, Hugging Face, a company that hosts much of the world’s AI software and open-source AI models, was hacked. A malicious dataset had been used to run code on one of its servers. Whoever was behind it captured internal security credentials and moved through systems over a weekend, running thousands of actions from a swarm of temporary server environments. It looked like the work of a sophisticated criminal group.
It was not. It was one of OpenAI’s new, still unreleased GPT models...
https://www.schneier.com/blog/archives/2026/07/measuring-the-tendency-of-ai-agents-to-go-rogue.html
Microsoft’s Secure Boot has had a serious vulnerability for most of its existence.
An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the software company anyway.
The images are known as shims, which were invented to extend Secure Boot to Linux devices and utility software. Using a technique simple enough to be performed by novice hackers, these old, forgotten shims can be used to completely circumvent the protection, which is embedded into the UEFI (Unified Extensible Firmware Interface) of the device’s motherboard. The gaffe is the result of the failure by Microsoft, which oversees the signing of shims, to revoke the publicly available images once vulnerabilities were found in them...
There’s new benchmark measuring AI’s ability to perform mathematical cryptanalysis. Anthropic’s frontier model actually found new attacks.
The benchmark: “CryptanalysisBench: Can LLMs do Cryptanalysis?” The idea is to benchmark the ability of LLMs to discover new mathematical cryptanalytic attacks against a series of historical algorithms.
Abstract: Cryptanalysis—the task of finding attacks against cryptographic schemes—its at the intersection of mathematical reasoning and cybersecurity, two areas where LLMs have advanced fastest. Cryptanalysis represents both a clean testbed for frontier reasoning (as practical attacks can be automatically verified) and a domain with unusually high stakes, since the primitives under study underpin our digital security. In this paper we ask whether LLMs can do cryptanalysis, and find that the answer is increasingly yes. We introduce CryptanalysisBench, 191 tasks across six families of cryptographic primitives (block ciphers, hash functions, etc.) drawn primarily from four NIST standardization competitions. Our benchmark consists of three tiers: (i) primitives with known practical breaks; (ii) primitives with no known practical break, evaluated both at full strength and as scaled-down variants; and (iii) a challenge set of production primitives at the frontier of cryptanalysis. Five frontier models (Claude Opus 4.8, Sonnet 5, Mythos 5, GPT-5.5, and the open-weights GLM-5.2) break 65%86% of Tier 1 schemes, 612 Tier-2 schemes at full strength, and 2461 across all scaled-down variants. Beyond deriving known results, models produce novel cryptanalysis, such as a key-recovery attack that exploits a design flaw in the SpoC AEAD and an error in KINDI’s published CCA-security proof, both to the best of our knowledge not previously known...
https://www.schneier.com/blog/archives/2026/07/measuring-llms-ability-to-perform-cryptanalysis.html
Governments are switching, but I’m not sure it makes a difference:
...some municipalities, including Denver, Colorado, are ditching their Flock arrays. But keep in mind that if they’re only switching from Flock to another brand of license-plate readers, like Axon, it’s like a gambling addict trying to kick the habit by switching from FanDuel to DraftKings.
[...]
Despite what you may read on the Flock website, Axon cameras are pretty effective when it comes to hoovering up personal details that can go far beyond your license plate numbers. That means a municipality that opts for Axon cameras instead of Flock units won’t necessarily reduce the amount privacy its citizens lose through their use...
Yet another Israeli mass surveillance company:
Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops to keep tabs on any phones in the vicinity whether they’re owned by a suspect in a case or not. Cognyte’s contract with the state of Texas reveals that the simulator, called FalcoNet, can be concealed within the vehicles, hidden in a backpack for on-foot missions or attached to a helicopter. It’s the same technology as the infamous Stingray, one of the original cell-site simulators made by defense giant L3Harris...
https://www.schneier.com/blog/archives/2026/07/cognyte-sells-a-mobile-cell-surveillance-van.html