I added hover over text, it messed up some of the formatting. But whatever, I gotta go write my TPS report.

Krebs on Security

Dark Reading

The Hacker News [ THN ] - Best Security Blog

2026-07-28 - Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
2026-07-28 - Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
2026-07-27 - NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
2026-07-27 - Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
2026-07-27 - Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
2026-07-27 - ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
2026-07-27 - n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
2026-07-27 - Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
2026-07-27 - Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
2026-07-27 - TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
2026-07-27 - GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
2026-07-26 - Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
2026-07-25 - Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
2026-07-25 - Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
2026-07-25 - CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
2026-07-25 - Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
2026-07-25 - DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
2026-07-24 - BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
2026-07-24 - Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
2026-07-24 - ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
2026-07-24 - Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
2026-07-24 - Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
2026-07-24 - Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
2026-07-24 - Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
2026-07-24 - NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
2026-07-24 - Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
2026-07-24 - Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
2026-07-24 - Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

Schneier on Security

2026-07-27 - mass surveillance company:

Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops to keep tabs on any phones in the vicinity ­ whether they’re owned by a suspect in a case or not. Cognyte’s contract with the state of Texas reveals that the simulator, called FalcoNet, can be concealed within the vehicles, hidden in a backpack for on-foot missions or attached to a helicopter. It’s the same technology as the infamous Stingray, one of the original cell-site simulators made by defense giant L3Harris...

">Cognyte Sells a Mobile Cell Surveillance Van
2026-07-24 - this year.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

">Friday Squid Blogging: Illex Squid Catch in the Falklands
2026-07-24 - IEEE Spectrum.

Major benchmarks measure what AI can do. None measure whether it does what you mean: the distance between what you ask an AI to do and the unspoken assumptions about how you want the AI to do it. We propose a new metric: the Genie coefficient.

There’s often a gap between one person’s request and another’s understanding. Most of the time, we bridge it using general knowledge. For example, if you ask a friend to get you coffee, they’ll pour a cup from the pot or buy one from a coffee shop. They won’t bring you a bag of raw beans or snatch a cup from a stranger and hand it to you. You never specified any of this. You never had to...

">Why AI Needs a “Genie Coefficient”

ThreatPost

Sydney Morning Herald

New York Times

2026-07-28 - OpenAI Close to Landing $500 Billion Data Center With Backing From Nvidia
2026-07-27 - Apple Regains Spot Over Nvidia as Most Valuable Public Company
2026-07-27 - Microsoft Unveils A.I. Cybersecurity Tools
2026-07-27 - How Meta Got Everything It Wanted in a Secret Louisiana Data Center Deal
2026-07-27 - Nvidia Forms Alliance to Back Open-Source A.I. Amid Debate Over Safety
2026-07-27 - Why Restarting a Nuclear Power Plant Can Be Much Harder Than Expected
2026-07-26 - Why TikTok’s Algorithm Keeps You Trapped in a Breakup Loop
2026-07-27 - A Son of Wealth Finds His Calling in a High-End Grocery Store
2026-07-25 - Silicon Valley Splits Over Closing the Borders to Chinese A.I.
2026-07-25 - QR Codes Make Their Way Down Wedding Aisles
2026-07-24 - Meta Launches New Facebook Marketplace App Called Seller
2026-07-24 - OpenAI Models Go Rogue + Kimi K3 Freakout + A.I. Superforecasting
2026-07-24 - An A.I. Music F.A.Q.: Can I Remix Madonna? Is This All Legal?
2026-07-24 - Judge Extends Pause for Paramount-Warner Bros. Deal

Wall Street Journal

BBC

2026-07-27 - Is it time to stop using glue and labels on paper?
2026-07-27 - Some people's chats with Claude AI found publicly available online
2026-07-27 - Why budding birders are flocking to Shazam-like apps to identify avians
2026-07-25 - Warning shot or publicity stunt - how worried should we be about the OpenAI hack?
2026-07-24 - PlayStation Network outage resolved after thousands of gamers unable to play
2026-07-24 - Trump vows to investigate EU over fining of US tech companies
2026-07-24 - How Jimothy the raccoon became the internet's latest animal obsession
2026-07-25 - Tech Now

SecurityBrief AU

ITNews AU

2026-07-28 - ASD to critical infrastructure ops: be ready to isolate systems for three months
2026-07-27 - Fake Corepack tool site goes quiet after luring devs with malware
2026-07-27 - Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week
2026-07-24 - Google rolls out new selfie video sign-in feature
2026-07-24 - US and allies say Russian hackers stole emails without social engineering

BleepingComputer

2026-07-27 - Hackers target US firms in FastJson RCE zero-day attacks
2026-07-27 - Arista patches VeloCloud Orchestrator zero-day exploited in attacks
2026-07-27 - New Dysphoria DDoS botnet spreads to 200k devices worldwide
2026-07-27 - New Certighost PoC exploit lets attackers hijack Windows domains
2026-07-27 - Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin
2026-07-27 - Coca-Cola confirms data theft in Fairlife ransomware attack
2026-07-27 - Ernst & Young data breach claimed by ShinyHunters extortion gang
2026-07-27 - Shadow AI agents are multiplying. Here's how to find and secure them.
2026-07-26 - GitHub, PyPI add time-based defenses against supply chain attacks
2026-07-25 - Steam forum ClickFix attacks infect gamers with XMRig cryptominers
2026-07-25 - Malicious sites use JavaScript to build malware in browser memory
2026-07-25 - ShinyHunters data leaks fuel $2,000 sextortion email scam
2026-07-25 - OpenAI confirms ChatGPT is down worldwide
2026-07-24 - OnTrac notifies customers of data breach after network hack
2026-07-24 - Hermes AI agent used to automate attack on Thai Finance Ministry

/r/NetSec

2026-07-27 - /u/EatonZ
[link] [comments]">Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles
2026-07-27 - /u/DataBaeBee
[link] [comments]">Pollard's P-1 Factoring Algorithm in Plain C
2026-07-27 -

CVE-2026-61511 - a critical vulnerability in vBulletin that allows an unauthenticated attacker to execute arbitrary code on a remote server.

submitted by
/u/SSDisclosure
[link] [comments]">New vBulletin Vulnerability!
2026-07-24 - /u/natcoba
[link] [comments]">Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331

/r/InfoSecNews