CYBERSECURITY INTEL FREE'Dself-hosted CTI

LATEST // SURFACE WEB

Aggregated cybersecurity reporting, advisories and research. 406 matching records.
AUTO-POLL // 2026-08-16 06:25 UTC
SURFACE WEB DARK / DEEP WEB
RESET
2026-08-03 10:00 UTC
Vendor Research
TIER 2

30 days with Claude Mythos Preview: How Tenable adapted our security program, and why yours is next

Tenable Blog · Blake Kizer · indexed 2026-08-16 02:02 UTC

Tenable spent 30 days running frontier AI models against our own code. It didn’t just find bugs — it proved they’re real, with reproducible exploits. That fundamentally changes code security from ranking potential code defects to a much higher signal focused on the findings that matter. Read on to learn how it reshaped our security team's work, what it cost, and why your program is next.Key takeaways:Now code security starts with proof, not suspicions. Frontier AI instantly builds working exploits and proves which flaws are genuinely dangerous in your source code. Now remediations are confirm…

AI SecurityCloud SecuritySecurity Research
P0
2026-08-03 08:00 UTC
Vendor Research
TIER 2

Rapid7 Expands UK and Ireland Channel Presence Through Strategic Partnership with Exclusive Networks

Rapid7 · Ross Baker · indexed 2026-08-16 02:02 UTC

Ross Baker is Senior Director, Northern Europe at Rapid7.As organizations across the United Kingdom and Ireland embrace AI, cloud technologies, and digital transformation in the name of enhancing customer experiences and accelerating business growth, the cybersecurity landscape must continue to evolve just as quickly.In this environment, business leaders still expect security to enable innovation, not slow it down. They're pushed to reduce risk, improve visibility across expanding attack surfaces, and respond faster than ever before, with limited resources now table stakes. This is precisely …

P0
2026-07-31 21:01 UTC
Vendor Research
TIER 2

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-08-16 02:02 UTC

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft appeared first on Microsoft Security Blog.

MalwareMicrosoftPhishingThreat Actors
P0
2026-07-31 19:44 UTC
Vendor Research
TIER 2

HIPAA Security Rule on AWS – Technical Safeguards Implementation and Readiness Guidance

AWS Security Blog · Abdul Javid · indexed 2026-08-16 02:02 UTC

Today, we’re releasing the HIPAA Security Rule on AWS: Technical Safeguards Implementation and Readiness Guidance. This helps covered entities and business associates configure, implement, and evidence compliance with the HIPAA Security Rule Technical Safeguard requirements (45 CFR §164.312) when building healthcare workloads on AWS. The HIPAA Security Rule’s Technical Safeguards (§164.312) define five standards and […]

Cloud Security
P0
2026-07-31 18:13 UTC
Security Journalism
TIER 3

CISA Issues Fresh SBOM Guidance. Did They Get It Right?

Dark Reading · Nate Nelson · indexed 2026-08-16 02:02 UTC

A couple dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improvements.

P0
2026-07-31 13:19 UTC
Security Journalism
TIER 3

DROP Platform Lets Californians Reduce Digital Footprint

Dark Reading · Arielle Waldman · indexed 2026-08-16 02:02 UTC

Hundreds of thousands of California residents have already registered for the Delete Request and Opt-out Platform (DROP), which launches Aug. 1. Other states could follow if the process goes smoothly.

P0
2026-07-31 13:00 UTC
Security Journalism
TIER 3

USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports

Dark Reading · Alexander Culafi · indexed 2026-08-16 02:02 UTC

The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the correct categories.

P0
2026-07-31 11:53 UTC
Vendor Research
TIER 2

Rapid7 at Black Hat USA 2026: See preemptive security in action

Rapid7 · Emma Burdett · indexed 2026-08-16 02:02 UTC

Black Hat USA returns to Mandalay Bay in Las Vegas this August, bringing together security practitioners, researchers, and leaders from around the world. Rapid7 will be there in the Business Hall, with new capabilities, live demonstrations, expert-led sessions, and two days of activities at the Border Grill.This year, our focus is preemptive security: helping security teams anticipate credible risk, respond at machine speed, and maintain an accurate view of their security and compliance posture as their environment changes.Visit the Rapid7 booth at Black Hat USAYou can find Rapid7 at booth #2…

AI SecurityCloud SecurityDFIRSecurity ResearchThreat IntelligenceVulnerabilities
P0
2026-07-31 10:00 UTC
Vendor Research
TIER 2

The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

Palo Alto Networks Unit 42 · Adva Gabay and Noa Dekel · indexed 2026-08-16 02:02 UTC

Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appeared first on Unit 42.

AppleMalware
P0
2026-07-31 09:34 UTC
Vendor Research
TIER 2

Influence Operations Bulletin Q2 2026

Google Security Blog · Trust & Safety · indexed 2026-08-16 02:02 UTC

This bulletin includes coordinated influence operation campaigns terminated on our platforms in Q2 2026. It was last updated on June 30, 2026.AprilWe terminated 13 YouTu…

P0
2026-07-30 21:49 UTC
Vendor Research
TIER 2

Balancing speed and safety: A control framework for AI coding agents

AWS Security Blog · Daniel Begimher · indexed 2026-08-16 02:02 UTC

AI coding agents are part of the developer toolchain. Tools like Kiro and Claude Code generate features, tests, and code refactors from natural-language prompts. A single agent can open dozens of pull requests (PRs) across your repositories in an afternoon. That productivity comes with a trade-off: agents optimize for task completion at machine speed with […]

P0
2026-07-30 21:16 UTC
Security Journalism
TIER 3

Minnesota Water Utility Attacks Expose Sector's Cyber-Risks

Dark Reading · Jai Vijayan · indexed 2026-08-16 02:02 UTC

A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.

P0
2026-07-30 20:15 UTC
Vendor Research
TIER 2

What water utilities need to know about cybersecurity compliance

Tenable Blog · Kate Boronkay · indexed 2026-08-16 02:02 UTC

As federal enforcement tightens and states begin stepping in with their own cybersecurity mandates, water and wastewater utilities face a looming wave of hard compliance deadlines, compounded by recent cyber attacks on state water utilities.Key takeawaysWhile the EPA’s national sanitary-survey mandate stalled in court, the agency is aggressively using existing authority, technical guidance, and enforcement alerts to inspect cyber gaps. Community water systems serving 3,301 to 49,999 people, the vast majority of U.S. systems, must certify their Risk and Resilience Assessments (RRAs) by June 30…

DFIRThreat Intelligence
P0
2026-07-30 19:40 UTC
Security Journalism
TIER 3

AI Harnesses Burst With Potential Exploit Opps

Dark Reading · Robert Lemos · indexed 2026-08-16 02:02 UTC

A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors.

P0
2026-07-30 18:00 UTC
Vendor Research
TIER 2

You were onto something with “It’s the Climb,” Miley

Cisco Talos Intelligence Blog · Amy Ciminnisi · indexed 2026-08-16 02:02 UTC

Amy hikes Virginia’s most difficult trail and muses on the persistent challenges of cybersecurity. The two aren't dissimilar.

P0
2026-07-30 17:22 UTC
Vendor Research
TIER 2

Extend Amazon Inspector SBOM Generator with Plugins

AWS Security Blog · Michael Long · indexed 2026-08-16 02:02 UTC

Amazon Inspector is an automated vulnerability management service that continually scans Amazon Web Services (AWS) workloads for software vulnerabilities. The vulnerability management capabilities of Amazon Inspector are powered by an asset inventory engine known as the Amazon Inspector SBOM Generator (inspector-sbomgen), a standalone command-line tool that produces a software bill of materials (SBOM) from container […]

Cloud SecurityVulnerabilities
P0
2026-07-30 16:49 UTC
Independent Research
TIER 2

Read This Before You Buy That TV Streaming Stick

Krebs on Security · BrianKrebs · indexed 2026-08-16 02:02 UTC

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

Cybercrime
P0
2026-07-30 16:11 UTC
Vendor Research
TIER 2

KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails

Rapid7 · Rapid7 Labs · indexed 2026-08-16 02:02 UTC

OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, a critical vulnerability affecting Active Storage image processing when used in conjunction with the libvips image processing library. The vulnerability has a CVSSv4 score of 9.5 and is classified as Initialization of a Resource with an Insecure Default (CWE-1188). An unauthenticated attacker may be able to leverage CVE-2026-66066 and read files accessible to the Rails application process, potentially exposing secrets that could enable remote code execution (RCE) or access to connected system…

Vulnerabilities CVE-2026-66066
P50
2026-07-30 16:05 UTC
Vendor Research
TIER 2

Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security

Tenable Blog · Ashley Lukeeram · indexed 2026-08-16 02:02 UTC

Canada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance.Key takeaways:Bill C-8 introduces stringent new cyber incident reporting requirements and heavy financial penalties for critical infrastructure operators. Eliminating network blind spots with a hybrid IT/OT discovery approach, including Safe Active Querying for isolated, hard-to-reach process-control systems, enables operators to establish a requir…

Cloud SecurityDFIRICS / OTThreat ActorsThreat IntelligenceVulnerabilities
P10
2026-07-30 16:00 UTC
Vendor Research
TIER 2

​​​​What’s new in Microsoft Security: July 2026

Microsoft Security Blog · Alym Rayani · indexed 2026-08-16 02:02 UTC

This month’s updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations that AI-powered operations depend on. The post ​​​​What’s new in Microsoft Security: July 2026 appeared first on Microsoft Security Blog.

Microsoft
P0
2026-07-30 15:28 UTC
Security Journalism
TIER 3

Claude Mythos — Hype vs. Reality: What Security Teams Need to Know

Dark Reading · Alexander Culafi · indexed 2026-08-16 02:02 UTC

In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is it?

P0
2026-07-30 15:14 UTC
Vendor Research
TIER 2

Rapid7 named a Leader in the IDC MarketScape: Worldwide MDR Service for Midmarket 2026 Vendor Assessment

Rapid7 · Rapid7 · indexed 2026-08-16 02:02 UTC

IDC has named Rapid7 a Leader in the 2026 Worldwide Managed Detection and Response Service for Midmarket 2026 Vendor Assessment (Doc #US52992326, July 2026). We believe this recognition and research highlights where MDR is heading.Many security programs are still built around a reactive sequence of detect, triage, and respond, but the timelines surrounding modern attacks have changed too quickly for that model to hold up on its own. Time-to-exploit has dropped from two years to 22 hours, while eCrime breakout time now sits at 29 minutes. In an environment like that, a program moving at human …

AI SecurityDFIRThreat IntelligenceVulnerabilities
P0
2026-07-30 14:29 UTC
Vendor Research
TIER 2

Metasploit Framework 6.5 Released

Rapid7 · The Metasploit Team · indexed 2026-08-16 02:02 UTC

Today we’re proud to announce that Metasploit Framework version 6.5 has been released. Over the past two years, with the help of countless contributors, we’ve added 422 new modules along with a whole slew of new features.Malleable C2 Profiles for HTTPOne of the latest and most requested features is support for Malleable C2 profiles across all current Meterpreter payloads. This feature enables users to load a standard profile into Meterpreter and change the shape of its HTTP(S) traffic. All Meterpreters, including Windows, Java, Python, PHP and Linux, have been updated with this functionality.…

AI SecurityLinuxMicrosoftVulnerabilities
P0
2026-07-30 14:00 UTC
Vendor Research
TIER 2

Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. However, Google Threat Intelligence Group (GTIG) has been tracking growth in threat activity targeting open source software repositories to conduct supply chain compromises over the past several years. A series of large scale open source s…

AI SecurityAppleAPT / Nation-StateCredential ExposureCybercrimeData BreachesDFIRLinuxMalwareRansomwareThreat ActorsThreat Intelligence
P15
2026-07-30 10:35 UTC
Vendor Research
TIER 2

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Rapid7 · Rapid7 · indexed 2026-08-16 02:02 UTC

OverviewOn July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server.CVECVSSv3.1Description SummaryCVE-2026-593099.8 (Critical)An authentication bypass vulnerability in the VMware Directory Service of vCenter that could all…

MicrosoftVulnerabilities CVE-2026-59309CVE-2026-59310CVE-2026-593109
P50
2026-07-30 10:00 UTC
Vendor Research
TIER 2

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-16 02:02 UTC

Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42.

Threat Actors
P0
2026-07-30 10:00 UTC
Vendor Research
TIER 2

Black Hat special: Rewind and revisit

Cisco Talos Intelligence Blog · Amy Ciminnisi · indexed 2026-08-16 02:02 UTC

Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence.

Threat Intelligence
P0
678910