📡 Tech & Security Digest — 2026-08-02
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- ESET tracks rise in malicious AI skills and adaptable malware — Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET’s new threat report examines th…
- Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests — One of Anthropic’s Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real s…
- ShinyHunters claims Brinks Home breach, threatens to leak stolen data — Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. [….
- Rails patches critical Active Storage flaw with RCE potential — A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and p…
- JetBrains warns of critical TeamCity remote code execution flaw — JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code e…
- Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers — Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hacke…
- Google says AI helped Chrome fix 1,072 security bugs in two releases — Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,…
Krebs on Security
- Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple…
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm — Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tr…
- Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts — South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers u…
- Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation — The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerabi…
- Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass — Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Mana…
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw — A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild….
- ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories — A lot of security still comes down to trusting the wrong screen.
This week, that screen might be a login page, an install guide, a recruiter call, or…
- Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Ma…
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory — Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and Open…
- JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach — JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluatio…
- Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database — A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service’s Gremlin query sandbox and obtain full read and write ac…