(Adobe Stock) Medusa ransomware group attacked more than 500 victims since 2021Steve ZurierAugust 19, 2026Medusa ransomware hit 500-plus victims, exploiting critical flaws at increasing speed.
Why regulated industries can’t afford to skip data privacy for their AI projectsDavid BalabanAugust 17, 2026
The Water Watch Center promises the cyber protection small water utilities needJohn Gallagher August 14, 2026
Inside Mythos: A CSO’s technical decoder for Anthropic’s autonomous offensive AIPaul WagenseilAugust 17, 2026
Ready for the flood: How exposure management prepares you for the Mythos vulnerability onslaughtPaul WagenseilAugust 14, 2026
Malware‘TWINLOOT’ Python implant abuses Microsoft services for stealthy C2Laura FrenchAugust 19, 2026The implant ensures defenders only see legit Microsoft services rather than unknown external domains, making it more challenging to block attacks.
RansomwareCISA confirms 2025 Windows Task Host flaw exploited by ransomware groupsSteve ZurierAugust 18, 2026Experts say teams should make this a priority, noting that the patch has been available since last November.
AI/MLWiz agent finds Snowflake repo flaw in code co-authored by GitHub Copilot AutofixLaura FrenchAugust 18, 2026The flaw allowed the agent to extract a Jira token by opening a crafted issue.
Vulnerability ManagementCritical SAP Commerce Cloud flaw exploited days after patchSteve ZurierAugust 17, 2026Attackers moved quickly to exploit a critical SAP Commerce Cloud bug following its patch.
RansomwareMacOS AmnesiaStealer malware spread through ClickFix, grants live browser controlLaura FrenchAugust 14, 2026A fake GitHub download page hosts the malicious ClickFix command.
Critical Infrastructure SecurityAI-driven energy buildout raises cybersecurity, supply chain risksSC StaffAugust 14, 2026AI-driven energy growth brings new cyber and supply chain risks to critical infrastructure.
Critical Infrastructure SecurityWhite House looks to engage private sector in offensive hacking opsSteve ZurierAugust 14, 2026Trump expands private-sector role in U.S. offensive cyber operations, raising governance concerns.
Threat ManagementDPRK’s Lazarus Group exploits Windows zero-day in backdoor campaignLaura FrenchAugust 14, 2026Initial access is gained through fake job offers and PDF viewer downloads.