Showing 30 of 30 articles.
Showing 30 of 30 articles from 3 sources • Last updated
Current issue 30 articles 3 sources RSS archive
RSS source coverage
3 active feeds 2 quiet feeds health only
Source shortcut: All active feeds (30 articles)
RSS feed 30 items
Digest legend: source signals and handoff cues
Source signals
Industry mediaSecurity news reporting
Handoff cues
SentryInsight: incident watchPotential incident or compromise follow-upSentryInsight: vuln triageVulnerability or exploitation reviewSentryInsight: vendor watchVendor or product-owner trackingSentryInsight: monitorLow-signal item worth monitoring
Critical Bleeping Computer bleepingcomputer.com Industry media Fresh - 4h old

Estée Lauder discloses data breach via Oracle E-Business flaw

NEW
VulnerabilityExploitationData Breach
SentryInsight: incident watchSentryInsight: vuln triage
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human Show full summary

resources (HR) operations. [...]...

Critical Bleeping Computer bleepingcomputer.com Industry media Fresh - 4h old

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

NEW
VulnerabilityExploitationMalware
SentryInsight: incident watchSentryInsight: vuln triage
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on Show full summary

vulnerable VPN appliances. [...]...

Monitor Bleeping Computer bleepingcomputer.com Industry media Fresh - 4h old

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

NEW
SentryInsight: monitor
The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain Show full summary

infrastructure used to feed prices into the protoc...

Elevated Dark Reading darkreading.com Industry media Fresh - 5h old

'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

NEW
VulnerabilityExploitation
SentryInsight: vuln triage
Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest Show full summary

attack surfaces on the Internet....

Monitor Bleeping Computer bleepingcomputer.com Industry media Fresh - 6h old

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

NEW
GoogleAI Security
SentryInsight: vendor watch
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple Show full summary

CVEs, patches, and Google downgrading two ...

Critical Bleeping Computer bleepingcomputer.com Industry media Fresh - 6h old

JadePuffer agentic attacks now target AI model data with ransomware

NEW
RansomwareMalwareAI Security
SentryInsight: incident watch
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector Show full summary

databases, and model checkpoints. [...]...

Elevated Dark Reading darkreading.com Industry media Fresh - 6h old

Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push

NEW
IvantiVulnerability
SentryInsight: vuln triageSentryInsight: vendor watch
Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages; but cost and human-in-the-loop viability remain open Show full summary

questions....

Monitor Dark Reading darkreading.com Industry media Fresh - 8h old

CISOs Feel the Heat Over AI Risk

NEW
AI Security
SentryInsight: monitor

Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position....

Elevated Dark Reading darkreading.com Industry media Fresh - 8h old

Attackers Combo Up Evasion Tactics for BEC Phishing

NEW
Identity
SentryInsight: incident watch
"The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Show full summary

Best Private Logger....

Elevated The Hacker News thehackernews.com Industry media Fresh - 8h old

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

NEW
GitHubMalwareAI Security
SentryInsight: vendor watch
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Show full summary

Model Context Protocol (MCP) servers to ...

Critical Bleeping Computer bleepingcomputer.com Industry media Fresh - 9h old

New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

NEW
MicrosoftData BreachMalware
SentryInsight: incident watchSentryInsight: vendor watch
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker Show full summary

commands and exfiltrate stolen data. [......

Elevated The Hacker News thehackernews.com Industry media Fresh - 9h old

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

NEW
IdentityMalwareAI Security
SentryInsight: incident watch
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, Show full summary

execution experiments, droppers, builder ...

Elevated The Hacker News thehackernews.com Industry media Fresh - 12h old

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

NEW
MicrosoftMalware
SentryInsight: vendor watch
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out Show full summary

stolen files as attachments on calendar e...

Monitor Bleeping Computer bleepingcomputer.com Industry media Fresh - 13h old

An AI SOC Evaluation Guide for Security Leaders

NEW
AI Security
SentryInsight: monitor
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a Show full summary

practical framework for assessing AI SOC soluti...

Monitor Dark Reading darkreading.com Industry media Fresh - 13h old

Cybersecurity Keeps Events 'Uneventful'

NEW
SentryInsight: monitor
From the World Cup to the United States' 250th celebration, this year's event calendar has been packed with high-profile gatherings that drew global audiences, Show full summary

intense scrutiny, and enormous security ...

Critical The Hacker News thehackernews.com Industry media Fresh - 13h old

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

NEW
VulnerabilityAI Security
SentryInsight: incident watchSentryInsight: vuln triage
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security Show full summary

tools. The paths were often simple: exposed sys...

Elevated Bleeping Computer bleepingcomputer.com Industry media Fresh - 15h old

Hugging Face warns an autonomous AI agent hacked its network

NEW
IdentityAI Security
SentryInsight: incident watch
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production Show full summary

infrastructure using an autonomous AI age...

Monitor The Hacker News thehackernews.com Industry media Fresh - 15h old

Mythos Didn't Break Your Security Program. Your Exposure Window Could.

NEW
AI Security
SentryInsight: monitor
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded Show full summary

pipeline? How quickly would the flood of AI...

Monitor Bleeping Computer bleepingcomputer.com Industry media Fresh - 16h old

Microsoft confirms Windows Server Update Services sync delays

NEW
Microsoft
SentryInsight: vendor watch
Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a Show full summary

week. [...]...

Monitor Bleeping Computer bleepingcomputer.com Industry media Fresh - 17h old

Windows KB5121767 OOB update fixes shutdowns on some Dell PCs

NEW
Microsoft
SentryInsight: vendor watch
Microsoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates. Show full summary

[...]...

Critical Bleeping Computer bleepingcomputer.com Industry media Fresh - 17h old

Critical ServiceNow code execution flaw now exploited in attacks

NEW
VulnerabilityExploitationAI Security
SentryInsight: incident watchSentryInsight: vuln triage
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. Show full summary

[...]...

Elevated The Hacker News thehackernews.com Industry media Fresh - 18h old

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

NEW
Vulnerability
SentryInsight: vuln triage
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the Show full summary

archiver processes XZ chunked data, and Trend ...

Elevated The Hacker News thehackernews.com Industry media Fresh - 18h old

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

NEW
GoogleMalwareAI Security
SentryInsight: vendor watch
A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence Show full summary

(AI) and commandeered a live botnet. The f...

Monitor The Hacker News thehackernews.com Industry media Fresh - 21h old

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

NEW
AI Security
SentryInsight: monitor
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI Show full summary

agent system. The company said it detected...

Elevated The Hacker News thehackernews.com Industry media Fresh - 22h old

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

NEW
Supply Chain
SentryInsight: monitor
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were Show full summary

published to RubyGems with the end goal of s...

Elevated The Hacker News thehackernews.com Industry media Recent - 1d old

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

Vulnerability
SentryInsight: vuln triage
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted Show full summary

HTTP requests. CVE-2026-42533 was patched ...

Monitor Bleeping Computer bleepingcomputer.com Industry media Recent - 1d old

Hackers abuse ViPNet software to target Russian govt agencies

SentryInsight: monitor
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government Show full summary

agencies. [...]...

Elevated The Hacker News thehackernews.com Industry media Recent - 1d old

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Malware
SentryInsight: monitor
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines Show full summary

with data-stealing malware. According t...

Elevated The Hacker News thehackernews.com Industry media Recent - 1d old

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

Exploitation
SentryInsight: vuln triage
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN Show full summary

appliances as zero-days prior their public dis...